Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
📦
📦 npm
Not in CISA KEV
MEDIUM severity

CVE-2013-7035 — react

MEDIUMFix: facebook/react@393a889

CVE-2013-7035 is a medium-severity (CVSS 6.5) vulnerability in react. A fix is available for react — see the affected versions and patch details below.

Cross-Site Scripting in react

Published
Updated
Affected
2 pkgs
Patched
2 / 2
Exploits
None indexed
Exploitation data as of Nov 8, 2023 · OSV.dev, FIRST.org (EPSS)

Real-World Exposure

2 pkgs affected
📦react📦react

Real-time download stats are indexed for npm and PyPI packages. This vulnerability affects npm packages — download data is not available via public APIs for these ecosystems.

Description

Affected versions of react are vulnerable to Cross-Site Scripting (XSS). The package fails to properly sanitize input used to create keys. This may allow attackers to execute arbitrary JavaScript if a key is generated from user input.

Recommendation

If you are using react 0.5.x, upgrade to version 0.5.2 or later. If you are using react 0.4.x, upgrade to version 0.4.2 or later.

Affected Packages

2 total 2 fixed
EcosystemPackageVulnerable rangeFix
📦npmreact≥ 0.4.0&&< 0.4.20.4.2npm install react@0.4.2
📦npmreact≥ 0.5.0&&< 0.5.20.5.2npm install react@0.5.2

Detection & mitigation playbook

Open-source dependency
  1. Detect

    Scan your dependency tree (package-lock.json, pnpm-lock.yaml, requirements.txt, go.sum, etc.) for react, including transitive dependencies — a direct dependency you never call can still pull in a vulnerable version.

  2. Fix

    Update react to 0.4.2 or later, then make sure no transitive (indirect) dependency still pins the vulnerable range — O3 confirms CVE-2013-7035 is resolved across your whole dependency graph.

  3. Workarounds

    Escape or sanitise the affected output on the server side rather than relying on client-side filtering, and add a Content-Security-Policy that blocks inline script execution so injected markup cannot run even if it reaches the page.

Frequently Asked Questions

Affected versions of `react` are vulnerable to Cross-Site Scripting (XSS). The package fails to properly sanitize input used to create keys. This may allow attackers to execute arbitrary JavaScript if a key is generated from user input. ## Recommendation If you are using `react` 0.5.x, upgrade to version 0.5.2 or later. If you are using `react` 0.4.x, upgrade to version 0.4.2 or later.
O3 Security · Impact-Aware SCA

Is CVE-2013-7035 in your dependencies?

Find it across npm, including transitive dependencies.

CVE-2013-7035: react XSS — Fixed in 0.4.2