Executive brief
The @leanprover/unicode-input-component is a JavaScript library used in Lean Prover development tools to provide special character input functionality. A cross-site scripting (XSS) vulnerability allows attackers to inject malicious scripts through unescaped HTML handling, potentially compromising user sessions or stealing sensitive data in projects that integrate this component.
Technical details
The vulnerability is a reflected/stored XSS flaw (CWE-80) in @leanprover/unicode-input-component versions 0.1.9 and earlier. The component re-inserted text into the input element without proper HTML escaping, allowing arbitrary JavaScript execution. The attack requires user interaction (active participation by the user) over a network, but no authentication or elevated privileges are required. An attacker can inject malicious HTML/JavaScript through the unicode input field. The vulnerability has been patched in version 0.2.0 and higher.
Affected products
- Lean Prover unicode-input-component 0.1.9 and earlier
Timeline
- 2026-03-16: disclosed: Vulnerability advisory published
- 2026-03-16: patched: Fixed in version 0.2.0