IA Squad
SearchPT
js · devbridge-autocompleteHeads-up

devbridge-autocomplete: XSS via unescaped formatGroup and formatResult

The default `formatGroup` and `formatResult` functions concatenate values into HTML without escaping, leading to XSS vulnerabilities.

23 Jun 2026Read 1 minSeverity: schedule it

What changed

The default `formatGroup` and `formatResult` functions concatenate values into HTML without escaping, leading to XSS vulnerabilities. Fixed in version 2.0.1.

Who it affects

Applications using devbridge-autocomplete that render attacker-controllable suggestion data, especially those using `groupBy` or `minChars: 0`.

What to do today

Update devbridge-autocomplete to version 2.0.1 or later to patch the XSS vulnerabilities.

The trail
Collected Audited Written Published