ag-grid Cross-Site Scripting vulnerability
        
  High severity
        
          GitHub Reviewed
      
        Published
          Sep 2, 2020 
          to the GitHub Advisory Database
          •
          Updated Jul 10, 2025 
      
  
Description
        Reviewed
      Aug 31, 2020 
    
  
        Published to the GitHub Advisory Database
      Sep 2, 2020 
    
  
        Last updated
      Jul 10, 2025 
    
  
Versions of
ag-gridprior to 14.0.0 are vulnerable to Cross-Site Scripting (XSS). Grid contents are not properly sanitized and may allow attackers to execute arbitrary JavaScript if user input is rendered in the grid.Recommendation
Upgrade to version 14.0.0 or later.
References