{"id":"CVE-2018-6341","details":"React applications which rendered to HTML using the ReactDOMServer API were not escaping user-supplied attribute names at render-time. That lack of escaping could lead to a cross-site scripting vulnerability. This issue affected minor releases 16.0.x, 16.1.x, 16.2.x, 16.3.x, and 16.4.x. It was fixed in 16.0.1, 16.1.2, 16.2.1, 16.3.3, and 16.4.2.","aliases":["GHSA-mvjj-gqq2-p4hw"],"modified":"2026-03-14T09:30:17.677423Z","published":"2018-12-31T22:29:00.387Z","references":[{"type":"ADVISORY","url":"https://reactjs.org/blog/2018/08/01/react-v-16-4-2.html"},{"type":"ADVISORY","url":"https://twitter.com/reactjs/status/1024745321987887104"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/facebook/react","events":[{"introduced":"8765d608935a81ba5019f6cde6dce3367d392f0c"},{"fixed":"54adb2674afe16ec603e0c54bf46ccf1afa42308"}],"database_specific":{"versions":[{"introduced":"16.4.0"},{"fixed":"16.4.2"}]}}],"versions":["v16.4.0","v16.4.1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2018-6341.json","unresolved_ranges":[{"events":[{"introduced":"16.0.0"},{"fixed":"16.0.1"}]},{"events":[{"introduced":"16.1.0"},{"fixed":"16.1.2"}]},{"events":[{"introduced":"16.2.0"},{"fixed":"16.2.1"}]},{"events":[{"introduced":"16.3.0"},{"fixed":"16.3.3"}]}]}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"}]}