react-on-rails is vulnerable to Cross-site Scripting (XSS)
50
Medium Risk
Affected versions of this package are vulnerable to Cross-Site Scripting (XSS) due to insufficient escaping of user input in dynamic DOM selectors and JavaScript contexts, which could allow an attacker to inject malicious scripts through crafted inputs. This vulnerability stems from the lack of proper sanitization in component and store script generation, enabling arbitrary code execution. An attacker might exploit this by manipulating dynamic IDs without CSS.escape() or submitting unescaped user data that executes in other users' browsers, potentially leading to session hijacking or data theft.
You are affected if you are using a version that falls within the vulnerable range.
react-on-rails is vulnerable to Cross-site Scripting (XSS) in versions 11.0.8 - 16.0.1.
Upgrade the react-on-rails library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant