Vulnerability library
Security checkMarch 16, 2026

XSS in @leanprover/unicode-input-component

Understand the exposure, see the recommended fix, and check whether your own website has related weaknesses.

Check your website

Find this and other vulnerabilities with a free scan.

Your scan runs on your computer. No account required.

Description

Projects that use @leanprover/unicode-input-component are vulnerable to an XSS exploit in 0.1.9 of the package and lower. The component re-inserted text in the input element back into the input element as unescaped HTML.

Recommendation

Update the @leanprover/unicode-input-component package to the latest compatible version. Followings are version details:

  • Affected version(s): < 0.2.0
  • Patched version(s): 0.2.0

References

Could your website be exposed too?

SmartScanner can check your website for XSS in @leanprover/unicode-input-component and gives you actionable findings to investigate.

Start a free scan

Related Issues

See something that needs correcting? Let us knowUpdated March 16, 2026