{"id":"CVE-2018-6341","details":"React applications which rendered to HTML using the ReactDOMServer API were not escaping user-supplied attribute names at render-time. That lack of escaping could lead to a cross-site scripting vulnerability. This issue affected minor releases 16.0.x, 16.1.x, 16.2.x, 16.3.x, and 16.4.x. It was fixed in 16.0.1, 16.1.2, 16.2.1, 16.3.3, and 16.4.2.","aliases":["GHSA-mvjj-gqq2-p4hw"],"modified":"2026-08-27T03:48:13.660816084Z","published":"2018-12-31T22:29:00.387Z","database_specific":{"unresolved_ranges":[{"cpes":["cpe:2.3:a:facebook:react:*:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"16.0.0"},{"fixed":"16.0.1"},{"introduced":"16.1.0"},{"fixed":"16.1.2"},{"introduced":"16.2.0"},{"fixed":"16.2.1"},{"introduced":"16.3.0"},{"fixed":"16.3.3"}],"source":"CPE_RANGE","vendor_product":"facebook:react"}]},"references":[{"type":"ADVISORY","url":"https://reactjs.org/blog/2018/08/01/react-v-16-4-2.html"},{"type":"ADVISORY","url":"https://twitter.com/reactjs/status/1024745321987887104"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/react/react","events":[{"introduced":"8765d608935a81ba5019f6cde6dce3367d392f0c"},{"fixed":"54adb2674afe16ec603e0c54bf46ccf1afa42308"}],"database_specific":{"source":"CPE_RANGE","cpe":"cpe:2.3:a:facebook:react:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"16.4.0"},{"fixed":"16.4.2"}]}}],"versions":["v16.4.1","v16.4.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2018-6341.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"}]}