Back to search
CVE-2026-32732
Published: Mar 13, 2026
Modified: Mar 16, 2026
PUBLISHED
Description
Lean 4 VS Code Extension is a Visual Studio Code extension for the Lean 4 proof assistant. Projects that use @leanprover/unicode-input-component are vulnerable to an XSS exploit in 0.1.9 of the package and lower. The component re-inserted text in the input element back into the input element as unescaped HTML. The issue has been resolved in 0.2.0.
| Vendor | Product | Versions |
|---|---|---|
leanprover | vscode-lean4 | affected < 0.2.0 |
Weaknesses (CWE)
References
https://github.com/leanprover/vscode-lean4/pull/735
x_refsource_MISC
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now