Description
Projects that use @leanprover/unicode-input-component are vulnerable to an XSS exploit in 0.1.9 of the package and lower. The component re-inserted text in the input element back into the input element as unescaped HTML.
Recommendation
Update the @leanprover/unicode-input-component package to the latest compatible version. Followings are version details:
- Affected version(s): < 0.2.0
- Patched version(s): 0.2.0
References
Could your website be exposed too?
SmartScanner can check your website for XSS in @leanprover/unicode-input-component and gives you actionable findings to investigate.
Start a free scanRelated Issues
- HAX CMS: Stored XSS via '<video-player>' component allows arbitrary JavaScript execution and token theft - CVE-2026-46496
- Open WebUI has Stored XSS in Banner Component via Improper Sanitization Order - CVE-2026-45665
- billboard.js is vulnerable to XSS during chart option binding - CVE-2026-1513
- Lobe Chat affected by Cross-Site Scripting(XSS) that can escalate to Remote Code Execution(RCE) - CVE-2026-23733


