The RepoCard component is vulnerable to Reflected Cross-Site Scripting (XSS). The vulnerability occurs because the component uses React's dangerouslySetInnerHTML to render the repository name (repo prop) during the loading state without any sanitization.
If a developer using this package passes unvalidated user input directly into the repo prop (for example, reading it from a URL query parameter), an attacker can execute arbitrary JavaScript in the context of the user's browser.
import { RepoCard } from 'repostat';
function App() {
const params = new URLSearchParams(window.location.search);
const maliciousRepo = params.get('repo') || 'facebook/react';
return <RepoCard repo={maliciousRepo} token="YOUR_TOKEN" />;
}
Update to version 1.0.1. The use of dangerouslySetInnerHTML has been removed, and the repo prop is now safely rendered using standard React JSX data binding, which automatically escapes HTML entities.
{
"cwe_ids": [
"CWE-79"
],
"github_reviewed": true,
"github_reviewed_at": "2026-02-25T16:04:41Z",
"nvd_published_at": "2026-02-25T03:16:05Z",
"severity": "MODERATE"
}