Skip to content
Vivek Kumar SinghVivek Kumar Singh

Share this article

VivekUI

Security in a Component Library: href Validation and CSV Injection

Security in a Component Library: href Validation and CSV Injection
Security in a Component Library: href Validation and CSV Injection

Security in a Component Library: href Validation and CSV Injection

React 18 renders a javascript: URL verbatim, so a CMS-fed link is a stored-XSS vector. And a CSV cell starting with = can execute in Excel. Two real attack paths a UI library should close for you.

vivekkumarsingh.in/blog/vivekui-security-href-csv-injection

Copy link

https://vivekkumarsingh.in/blog/vivekui-security-href-csv-injection

Share on social media

Cross-post to blogging platforms

Clicking any platform copies the canonical URL to your clipboard and opens the editor. Paste it as the article's canonical URL to keep all SEO signals on this domain.