CVE Database
/

CVE-2026-32732

Back to search

CVE-2026-32732

Published: Mar 13, 2026

Modified: Mar 16, 2026

PUBLISHED

Description

Lean 4 VS Code Extension is a Visual Studio Code extension for the Lean 4 proof assistant. Projects that use @leanprover/unicode-input-component are vulnerable to an XSS exploit in 0.1.9 of the package and lower. The component re-inserted text in the input element back into the input element as unescaped HTML. The issue has been resolved in 0.2.0.

VendorProductVersions

leanprover

vscode-lean4

affected
< 0.2.0

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now