astro
Warn
Audited by Socket on Sep 11, 2026
1 alert found:
AnomalyAnomalyevals/files/search-panel.jsx
LOWAnomalyLOW
evals/files/search-panel.jsx
The code does not show intentional malware, credential theft, obfuscation, or direct code injection. It contains a significant logic and availability issue because the effect updates values included in its own dependency array, causing repeated fetches. The caller-controlled endpoint may also permit unintended client-side data transmission if endpoint is not trusted. React's normal escaping mitigates direct XSS through r.title.
Confidence: 99%Severity: 55%
Audit Metadata