Projects that use @leanprover/unicode-input-component are vulnerable to an XSS exploit in 0.1.9 of the package and lower. The component re-inserted text in the input element back into the input element as unescaped HTML.
The issue has been resolved in 0.2.0.
Replace the unicode input component with a basic HTML text field.
{
"cwe_ids": [
"CWE-80"
],
"github_reviewed": true,
"github_reviewed_at": "2026-03-16T16:39:55Z",
"nvd_published_at": "2026-03-16T14:19:43Z",
"severity": "LOW"
}