context-mode is vulnerable to Cross-Site Scripting (XSS)
56
Medium Risk
The search results page rendered r.highlighted directly into the DOM using dangerouslySetInnerHTML without escaping/sanitization. If r.highlighted could be influenced by indexed or backend content, this enables HTML/JS injection.
You are affected if you are using a version that falls within the vulnerable range.
context-mode is vulnerable to Cross-Site Scripting (XSS) in versions 1.0.81 - 1.0.89.
Upgrade the context-mode library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant