inferno-server is vulnerable to CSS Injection
55
Medium Risk
Affected versions of this package are vulnerable due to a flaw in inferno-server's server-side rendering pipeline where the style prop bypasses HTML entity escaping during renderToString() or renderToStringStream(), allowing an attacker who controls an untrusted style value (e.g., from a CMS, theme, or user API) to inject raw attributes like onmouseover by breaking out of the style context, leading to Cross-Site Scripting (XSS).
You are affected if you are using a version that falls within the vulnerable range.
inferno-server is vulnerable to CSS Injection in versions 3.6.0 - 9.0.6.
Upgrade the inferno-server library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant