{"id":"CVE-2026-32732","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-32732","summary":"XSS in @leanprover/unicode-input-component","details":"### Impact\nProjects that use [@leanprover/unicode-input-component](https://www.npmjs.com/package/@leanprover/unicode-input-component) are vulnerable to an XSS exploit in 0.1.9 of the package and lower. \nThe component re-inserted text in the input element back into the input element as unescaped HTML.\n\n### Patches\nThe issue has been resolved in 0.2.0.\n\n### Workarounds\nReplace the unicode input component with a basic HTML text field.","published":"2026-03-16T16:39:55Z","modified":"2026-03-16T16:56:19.366316Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"@leanprover/unicode-input-component","fixedVersion":"0.2.0"}],"fix":{"url":"https://github.com/leanprover/vscode-lean4/pull/735","label":"leanprover/vscode-lean4#735"},"references":[{"type":"WEB","url":"https://github.com/leanprover/vscode-lean4/security/advisories/GHSA-6ggm-pwr9-r5h2"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-32732"},{"type":"WEB","url":"https://github.com/leanprover/vscode-lean4/pull/735"},{"type":"PACKAGE","url":"https://github.com/leanprover/vscode-lean4"},{"type":"WEB","url":"https://leanprover.zulipchat.com/#narrow/channel/113488-general/topic/weird.20behavior.20in.20loogle.20searchbar/near/578502003"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-03-16T16:56:19.366316Z"}}