OSV 1.4.0 · github-reviewed · 修改于 2026-06-11 21:28
发布时间
2026-05-21 02:31
GitHub 审查时间
2026-06-11 21:28
NVD 发布时间
2026-05-21 02:16
源文件
advisories/github-reviewed/2026/05/GHSA-fvhg-p4hf-79x3/GHSA-fvhg-p4hf-79x3.json
Cross-Site Scripting (XSS) vulnerability in @cyntler/react-doc-viewer v1.17.1 allows remote attackers to execute arbitrary JavaScript via a crafted .txt file. The TXTRenderer component fails to sanitize file content and explicitly casts raw data as a ReactNode.