@ant-design/charts is vulnerable to Cross-Site Scripting (XSS).
Steps To Reproduce
Open https://www.npmjs.com/package/@ant-design/charts
Open Gallery https://charts.ant.design/demos/global/
Select any chart(Ex:pie chart https://charts.ant.design/demos/pie)
Edit in Codesandbox https://codesandbox.io/s/zdk6l
We can change the version("@ant-design/charts": "1.0.7") in package.json https://codesandbox.io/s/zdk6l?file=/package.json:131-160 see the screenshots.
Insert the xss payload in any of the type field in data. EX: type: 'a"><img src=x onerror=alert(1)>',