Vulnerabilities/

XSS in @leanprover/unicode-input-component

Severity:
Low

Description

Projects that use @leanprover/unicode-input-component are vulnerable to an XSS exploit in 0.1.9 of the package and lower. The component re-inserted text in the input element back into the input element as unescaped HTML.

Recommendation

Update the @leanprover/unicode-input-component package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
@leanprover/unicode-input-component
Anything's wrong? Let us know Last updated on March 16, 2026