CVE-2018-6341: Facebook React

Medium severity, CVSS 6.1. EPSS: 3.4% chance of exploitation in the next 30 days.

React applications which rendered to HTML using the ReactDOMServer API were not escaping user-supplied attribute names at render-time. That lack of escaping could lead to a cross-site scripting vulnerability. This issue affected minor releases 16.0.x, 16.1.x, 16.2.x, 16.3.x, and 16.4.x. It was fixed in 16.0.1, 16.1.2, 16.2.1, 16.3.3, and 16.4.2.

Affected products

  • Facebook React: from 16.0.0, before 16.0.1 (fixed in 16.0.1); from 16.1.0, before 16.1.2 (fixed in 16.1.2); from 16.2.0, before 16.2.1 (fixed in 16.2.1); from 16.3.0, before 16.3.3 (fixed in 16.3.3); from 16.4.0, before 16.4.2 (fixed in 16.4.2)

Published 2018-12-31. Last modified 2026-06-17.