VDB
Sign up
MEDIUM6.5

GHSA-g53w-52xc-2j85

Cross-Site Scripting in react

Quick fix

GHSA-g53w-52xc-2j85 — react: upgrade to the fixed version with the command below.

npm install react@0.4.2

Details

Affected versions of `react` are vulnerable to Cross-Site Scripting (XSS). The package fails to properly sanitize input used to create keys. This may allow attackers to execute arbitrary JavaScript if a key is generated from user input.

## Recommendation

If you are using `react` 0.5.x, upgrade to version 0.5.2 or later. If you are using `react` 0.4.x, upgrade to version 0.4.2 or later.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/react
Introduced in: 0.4.0Fixed in: 0.4.2
Fixnpm install react@0.4.2
npm/react
Introduced in: 0.5.0Fixed in: 0.5.2
Fixnpm install react@0.5.2

References