CVE-2013-7035 is a medium-severity (CVSS 6.5) vulnerability in react. A fix is available for react — see the affected versions and patch details below.
Cross-Site Scripting in react
Real-World Exposure
react📦reactReal-time download stats are indexed for npm and PyPI packages. This vulnerability affects npm packages — download data is not available via public APIs for these ecosystems.
Description
Affected versions of react are vulnerable to Cross-Site Scripting (XSS). The package fails to properly sanitize input used to create keys. This may allow attackers to execute arbitrary JavaScript if a key is generated from user input.
Recommendation
If you are using react 0.5.x, upgrade to version 0.5.2 or later.
If you are using react 0.4.x, upgrade to version 0.4.2 or later.
Affected Packages
| Ecosystem | Package | Vulnerable range | Fix |
|---|---|---|---|
| 📦npm | react | ≥ 0.4.0&&< 0.4.2 | 0.4.2npm install react@0.4.2 |
| 📦npm | react | ≥ 0.5.0&&< 0.5.2 | 0.5.2npm install react@0.5.2 |
Detection & mitigation playbook
Open-source dependencyDetect
Scan your dependency tree (package-lock.json, pnpm-lock.yaml, requirements.txt, go.sum, etc.) for react, including transitive dependencies — a direct dependency you never call can still pull in a vulnerable version.
Fix
Update react to 0.4.2 or later, then make sure no transitive (indirect) dependency still pins the vulnerable range — O3 confirms CVE-2013-7035 is resolved across your whole dependency graph.
Workarounds
Escape or sanitise the affected output on the server side rather than relying on client-side filtering, and add a Content-Security-Policy that blocks inline script execution so injected markup cannot run even if it reaches the page.
Frequently Asked Questions
Is CVE-2013-7035 in your dependencies?
Find it across npm, including transitive dependencies.