CVE-2026-32732

Lean 4 VS Code Extension is a Visual Studio Code extension for the Lean 4 proof assistant. Projects that use @leanprover/unicode-input-component are vulnerable to an XSS exploit in 0.1.9 of the package and lower. The component re-inserted text in the input element back into the input element as unescaped HTML. The issue has been resolved in 0.2.0.
CVSS

No CVSS.

Configurations

No configuration.

History

No history.

Information

Published : 2026-03-16 14:19

Updated : 2026-03-16 14:53


NVD link : CVE-2026-32732

Mitre link : CVE-2026-32732

CVE.ORG link : CVE-2026-32732


JSON object : View

Products Affected

No product.

CWE
CWE-80

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)