syncfusion-aspnetcore-tree-view
Warn
Audited by Socket on Sep 22, 2026
1 alert found:
AnomalyAnomalyreferences/node-manipulation.md
LOWAnomalyLOW
references/node-manipulation.md
The code appears to be ordinary TreeView documentation/example code and shows no clear malware or supply-chain attack behavior. However, showPath contains a real XSS risk: node text is inserted into innerHTML without escaping. Use textContent and create separate elements, or HTML-escape the path before insertion. The synchronization and server-side behavior require review outside this fragment.
Confidence: 96%Severity: 55%
Audit Metadata