Description
Lean 4 VS Code Extension is a Visual Studio Code extension for the Lean 4 proof assistant. Projects that use @leanprover/unicode-input-component are vulnerable to an XSS exploit in 0.1.9 of the package and lower. The component re-inserted text in the input element back into the input element as unescaped HTML. The issue has been resolved in 0.2.0.
Published: 2026-03-13
Score: 0 Low
EPSS: < 1% Very Low
KEV: No
Impact: Cross‑Site Scripting in Lean 4 VS Code extension
Action: Apply Patch
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-6ggm-pwr9-r5h2 XSS in @leanprover/unicode-input-component
History

Mon, 16 Mar 2026 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 16 Mar 2026 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Leanprover
Leanprover vscode-lean4
Vendors & Products Leanprover
Leanprover vscode-lean4

Fri, 13 Mar 2026 22:00:00 +0000

Type Values Removed Values Added
Description Lean 4 VS Code Extension is a Visual Studio Code extension for the Lean 4 proof assistant. Projects that use @leanprover/unicode-input-component are vulnerable to an XSS exploit in 0.1.9 of the package and lower. The component re-inserted text in the input element back into the input element as unescaped HTML. The issue has been resolved in 0.2.0.
Title XSS in @leanprover/unicode-input-component
Weaknesses CWE-80
References
Metrics cvssV4_0

{'score': 0, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Leanprover Vscode-lean4
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-03-16T20:22:43.428Z

Reserved: 2026-03-13T15:02:00.627Z

Link: CVE-2026-32732

cve-icon Vulnrichment

Updated: 2026-03-16T20:20:37.687Z

cve-icon NVD

Status : Deferred

Published: 2026-03-16T14:19:43.580

Modified: 2026-04-16T14:57:08.337

Link: CVE-2026-32732

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-03-23T13:39:10Z

Weaknesses