syncfusion-aspnetcore-inline-ai-assist
Audited by Socket on Sep 22, 2026
2 alerts found:
Anomalyx2This is a benign UI demonstration with no apparent malware or supply-chain attack behavior. It contains two potential DOM XSS weaknesses: prompt/event data is inserted into the event log via innerHTML, and the accepted response is inserted into editable content via innerHTML without sanitization. Use textContent for logs and sanitize or safely construct DOM nodes for response content, especially when responses may come from an external AI service.
The fragment is documentation and sample UI code, not malware. It contains a potential DOM XSS vulnerability because an AI/component response is assigned directly to innerHTML without sanitization. Use textContent for plain text or sanitize the response with a well-configured HTML sanitizer before insertion. No evidence of supply-chain malware or unauthorized system activity is present.