VDB
Sign up
MEDIUM

GHSA-cg48-9hh2-x6mx

HTML Injection in preact

Quick fix

GHSA-cg48-9hh2-x6mx — preact: upgrade to the fixed version with the command below.

npm install preact@10.0.0-beta.1

Details

Versions of `preact` 10.x on prerelease tags alpha and beta prior to 10.0.0-beta.1 are vulnerable to HTML Injection. Due to insufficient input validation the package allows attackers to inject JavaScript objects as virtual-dom nodes, which may lead to Cross-Site Scripting. This requires user input parsed with `JSON.parse()` to be passed directly into JSX without sanitization.

## Recommendation

Upgrade to version 10.0.0-beta.1.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/preact
Introduced in: 10.0.0-alpha.0Fixed in: 10.0.0-beta.1
Fixnpm install preact@10.0.0-beta.1

References