Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 26 Jan 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 26 Jan 2026 12:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Dioxuslabs
Dioxuslabs components |
|
| Vendors & Products |
Dioxuslabs
Dioxuslabs components |
Sat, 24 Jan 2026 00:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Dioxus Components is a shadcn-style component library for the Dioxus app framework. Prior to commit 41e4242ecb1062d04ae42a5215363c1d9fd4e23a, `use_animated_open` formats a string for `eval` with an `id` that can be user supplied. Commit 41e4242ecb1062d04ae42a5215363c1d9fd4e23a patches the issue. | |
| Title | Dioxus Components has JavaScript injection via user-supplied IDs | |
| Weaknesses | CWE-94 CWE-95 |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-01-26T17:07:29.574Z
Reserved: 2026-01-23T00:38:20.547Z
Link: CVE-2026-24474
Updated: 2026-01-26T17:07:14.900Z
Status : Deferred
Published: 2026-01-24T00:15:49.603
Modified: 2026-04-15T00:35:42.020
Link: CVE-2026-24474
No data.
OpenCVE Enrichment
Updated: 2026-04-18T15:15:03Z