fig. 01 — GHSA-hg79-j56m-fxgv, the advisory selected below
// advisories
GHSA-hg79-j56m-fxgv
HIGH
Versions of react prior to 0.14.0 are vulnerable to Cross-Site Scripting (XSS). The package's createElement function fails to properly validate its input object, allowing attackers to execute arbitrary JavaScript in a victim's browser.