React applications which rendered to HTML using the ReactDOMServer API were not escaping user-supplied attribute names at render-time. That lack of escaping could lead to a cross-site scripting vulnerability. This issue affected minor releases 16.0.x, 16.1.x, 16.2.x, 16.3.x, and 16.4.x. It was fixed in 16.0.1, 16.1.2, 16.2.1, 16.3.3, and 16.4.2.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-mvjj-gqq2-p4hw | Cross-Site Scripting in react-dom |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Tue, 06 May 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: facebook
Published:
Updated: 2025-05-06T16:54:17.932Z
Reserved: 2018-01-26T00:00:00.000Z
Link: CVE-2018-6341
Updated: 2024-08-05T06:01:48.794Z
Status : Modified
Published: 2018-12-31T22:29:00.387
Modified: 2025-05-06T17:15:51.207
Link: CVE-2018-6341
No data.
OpenCVE Enrichment
No data.
Weaknesses
Github GHSA