Vulnerabilities/

Cross-Site Scripting in react (GHSA-g53w-52xc-2j85)

Severity:
Medium

Description

Affected versions of react are vulnerable to Cross-Site Scripting (XSS). The package fails to properly sanitize input used to create keys. This may allow attackers to execute arbitrary JavaScript if a key is generated from user input.

Recommendation

Update the react package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
react
Anything's wrong? Let us know Last updated on May 22, 2023