Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
📦 npm
Not in CISA KEV

ag-grid Cross-Site Scripting vulnerabilityGHSA-7p6w-x2gr-rrf8

Fix: ag-grid/ag-grid@b66b1dd

GHSA-7p6w-x2gr-rrf8 is a security vulnerability in ag-grid. A fix is available for ag-grid — see the affected versions and patch details below.

Published
Updated
Affected
1 pkg
Patched
1 / 1
Exploits
None indexed
Exploitation data as of Jul 10, 2025 · OSV.dev, FIRST.org (EPSS)

Real-World Exposure

1 pkg affected

How broadly this vulnerability is actually deployed: weekly install volume shows current usage, a proxy for how much of the ecosystem is exposed.

ag-gridnpm
13Kdownloads / week

Description

Versions of ag-grid prior to 14.0.0 are vulnerable to Cross-Site Scripting (XSS). Grid contents are not properly sanitized and may allow attackers to execute arbitrary JavaScript if user input is rendered in the grid.

Recommendation

Upgrade to version 14.0.0 or later.

Affected Packages

1 total 1 fixed
EcosystemPackageVulnerable rangeFix
📦npmag-gridall versions14.0.0npm install ag-grid@14.0.0

Detection & mitigation playbook

Open-source dependency
  1. Detect

    Scan your dependency tree (package-lock.json, pnpm-lock.yaml, requirements.txt, go.sum, etc.) for ag-grid, including transitive dependencies — a direct dependency you never call can still pull in a vulnerable version.

  2. Fix

    Update ag-grid to 14.0.0 or later, then make sure no transitive (indirect) dependency still pins the vulnerable range — O3 confirms GHSA-7p6w-x2gr-rrf8 is resolved across your whole dependency graph.

  3. Workarounds

    Escape or sanitise the affected output on the server side rather than relying on client-side filtering, and add a Content-Security-Policy that blocks inline script execution so injected markup cannot run even if it reaches the page.

Frequently Asked Questions

Versions of `ag-grid` prior to 14.0.0 are vulnerable to Cross-Site Scripting (XSS). Grid contents are not properly sanitized and may allow attackers to execute arbitrary JavaScript if user input is rendered in the grid. ## Recommendation Upgrade to version 14.0.0 or later.
O3 Security · Impact-Aware SCA

Is GHSA-7p6w-x2gr-rrf8 in your dependencies?

Find it across npm, including transitive dependencies.

ag-grid Cross-Site Scripting vulnerability