GHSA-6GGM-PWR9-R5H2

Vulnerability from github – Published: 2026-03-16 16:39 – Updated: 2026-03-16 16:39
VLAI
Summary
XSS in @leanprover/unicode-input-component
Details

Impact

Projects that use @leanprover/unicode-input-component are vulnerable to an XSS exploit in 0.1.9 of the package and lower. The component re-inserted text in the input element back into the input element as unescaped HTML.

Patches

The issue has been resolved in 0.2.0.

Workarounds

Replace the unicode input component with a basic HTML text field.

Show details on source website

{
  "affected": [
    {
      "package": {
        "ecosystem": "npm",
        "name": "@leanprover/unicode-input-component"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "0.2.0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "aliases": [
    "CVE-2026-32732"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-80"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2026-03-16T16:39:55Z",
    "nvd_published_at": "2026-03-16T14:19:43Z",
    "severity": "LOW"
  },
  "details": "### Impact\nProjects that use [@leanprover/unicode-input-component](https://www.npmjs.com/package/@leanprover/unicode-input-component) are vulnerable to an XSS exploit in 0.1.9 of the package and lower. \nThe component re-inserted text in the input element back into the input element as unescaped HTML.\n\n### Patches\nThe issue has been resolved in 0.2.0.\n\n### Workarounds\nReplace the unicode input component with a basic HTML text field.",
  "id": "GHSA-6ggm-pwr9-r5h2",
  "modified": "2026-03-16T16:39:55Z",
  "published": "2026-03-16T16:39:55Z",
  "references": [
    {
      "type": "WEB",
      "url": "https://github.com/leanprover/vscode-lean4/security/advisories/GHSA-6ggm-pwr9-r5h2"
    },
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-32732"
    },
    {
      "type": "WEB",
      "url": "https://github.com/leanprover/vscode-lean4/pull/735"
    },
    {
      "type": "PACKAGE",
      "url": "https://github.com/leanprover/vscode-lean4"
    },
    {
      "type": "WEB",
      "url": "https://leanprover.zulipchat.com/#narrow/channel/113488-general/topic/weird.20behavior.20in.20loogle.20searchbar/near/578502003"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N",
      "type": "CVSS_V4"
    }
  ],
  "summary": "XSS in @leanprover/unicode-input-component"
}



Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Forecast uses a logistic model when the trend is rising, or an exponential decay model when the trend is falling. Fitted via linearized least squares.

Sightings

Author Source Type Date Other

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or observed by the user.
  • Confirmed: The vulnerability has been validated from an analyst's perspective.
  • Published Proof of Concept: A public proof of concept is available for this vulnerability.
  • Exploited: The vulnerability was observed as exploited by the user who reported the sighting.
  • Patched: The vulnerability was observed as successfully patched by the user who reported the sighting.
  • Not exploited: The vulnerability was not observed as exploited by the user who reported the sighting.
  • Not confirmed: The user expressed doubt about the validity of the vulnerability.
  • Not patched: The vulnerability was not observed as successfully patched by the user who reported the sighting.

Loading…

Loading…

Loading…

Related by attack behaviour

Vulnerabilities whose description is nearest to this one in the vector space of the CIRCL/vulnerability-attack-technique-biencoder model. This is a similarity search over the bi-encoder space (plain cosine), not a classification, and it has no measured accuracy.


Loading…