HIGH
GHSA-hg79-j56m-fxgv
Cross-Site Scripting in react
Quick fix
GHSA-hg79-j56m-fxgv — react: upgrade to the fixed version with the command below.
npm install react@0.14.0Details
Versions of `react` prior to 0.14.0 are vulnerable to Cross-Site Scripting (XSS). The package's `createElement` function fails to properly validate its input object, allowing attackers to execute arbitrary JavaScript in a victim's browser.
## Recommendation
Upgrade to version 0.14.0 or later.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://github.com/facebook/react[PACKAGE]
- https://reactjs.org/blog/2015/10/07/react-v0.14.html#notable-enhancements[WEB]
- https://reactjs.org/blog/2019/10/22/react-release-channels.html#experimental-channel[WEB]
- https://snyk.io/vuln/npm:react:20150318[WEB]
- https://www.npmjs.com/advisories/1347[WEB]
- http://danlec.com/blog/xss-via-a-spoofed-react-element[WEB]