Intel

AIKIDO-2026-10194

@vnedyalk0v/react19-simple-maps is vulnerable to Cross-site Scripting (XSS)

Cross-site Scripting (XSS) Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Feb 21, 2026

50

Medium Risk

This Affects:

JS@vnedyalk0v/react19-simple-maps
1.0.5 - 2.0.1
Fixed in 2.0.2
Are you affected? Scan for Free

TL;DR

Affected versions of this package are vulnerable to cross-site scripting (XSS) through script-breakout in JSON-LD metadata. The MapMetadata component embeds JSON-LD inside a <script> tag without properly escaping special characters such as <, >, &, and certain Unicode separators, allowing attacker-controlled data to terminate the script context and inject arbitrary HTML or JavaScript.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

@vnedyalk0v/react19-simple-maps is vulnerable to Cross-site Scripting (XSS) in versions 1.0.5 - 2.0.1.

How to fix this

Upgrade the @vnedyalk0v/react19-simple-maps library to a patch version.