Vulnerability record · CVE-2018-6341 · published 31 December 2018
CVE-2018-6341: Facebook react cross-site scripting vulnerability
Facebook · React
React applications which rendered to HTML using the ReactDOMServer API were not escaping user-supplied attribute names at render-time. That lack of escaping could lead to a cross-site scripting vulnerability. This issue affected minor releases 16.0.x, 16.1.x, 16.2.x, 16.3.x, and 16.4.x. It was fixed in 16.0.1, 16.1.2, 16.2.1, 16.3.3, and 16.4.2.
Description
React applications which rendered to HTML using the ReactDOMServer API were not escaping user-supplied attribute names at render-time. That lack of escaping could lead to a cross-site scripting vulnerability. This issue affected minor releases 16.0.x, 16.1.x, 16.2.x, 16.3.x, and 16.4.x. It was fixed in 16.0.1, 16.1.2, 16.2.1, 16.3.3, and 16.4.2.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://reactjs.org/blog/2018/08/01/react-v-16-4-2.html | Vendor Advisory |
| https://twitter.com/reactjs/status/1024745321987887104 | Vendor Advisory |
| https://reactjs.org/blog/2018/08/01/react-v-16-4-2.html | Vendor Advisory |
| https://twitter.com/reactjs/status/1024745321987887104 | Vendor Advisory |
Track CVE-2018-6341 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2018-6341), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.