CVE-2026-24474: Dioxuslabs Components

Medium severity, CVSS 5.3. EPSS: 0.4% chance of exploitation in the next 30 days.

Dioxus Components is a shadcn-style component library for the Dioxus app framework. Prior to commit 41e4242ecb1062d04ae42a5215363c1d9fd4e23a, `use_animated_open` formats a string for `eval` with an `id` that can be user supplied. Commit 41e4242ecb1062d04ae42a5215363c1d9fd4e23a patches the issue.

Affected products

  • Dioxuslabs Components: before 41e4242ecb1062d04ae42a5215363c1d9fd4e23a (fixed in 41e4242ecb1062d04ae42a5215363c1d9fd4e23a)

Published 2026-01-24. Last modified 2026-06-17.