Description
Projects that use @leanprover/unicode-input-component are vulnerable to an XSS exploit in 0.1.9 of the package and lower. The component re-inserted text in the input element back into the input element as unescaped HTML.
Recommendation
Update the @leanprover/unicode-input-component package to the latest compatible version. Followings are version details:
- Affected version(s): < 0.2.0
- Patched version(s): 0.2.0
References
Related Issues
- HAX CMS: Stored XSS via '<video-player>' component allows arbitrary JavaScript execution and token theft - CVE-2026-46496
- Open WebUI has Stored XSS in Banner Component via Improper Sanitization Order - CVE-2026-45665
- billboard.js is vulnerable to XSS during chart option binding - CVE-2026-1513
- Lobe Chat affected by Cross-Site Scripting(XSS) that can escalate to Remote Code Execution(RCE) - CVE-2026-23733
You might also like:
- Tags:
- npm
- @leanprover/unicode-input-component
Anything's wrong? Let us know Last updated on March 16, 2026


