VYPR
Medium severityGHSA Advisory· Published Sep 4, 2020· Updated Oct 4, 2021

Cross-Site Scripting in react

CVE-2013-7035

Description

Affected versions of react are vulnerable to Cross-Site Scripting (XSS). The package fails to properly sanitize input used to create keys. This may allow attackers to execute arbitrary JavaScript if a key is generated from user input.

Recommendation

If you are using react 0.5.x, upgrade to version 0.5.2 or later. If you are using react 0.4.x, upgrade to version 0.4.2 or later.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
reactnpm
>= 0.4.0, < 0.4.20.4.2
reactnpm
>= 0.5.0, < 0.5.20.5.2

Affected products

2

Patches

Vulnerability mechanics

References

6

News mentions

0

No linked articles in our index yet.