@antv/g2
is vulnerable to Cross-Site Scripting (XSS)
.
npm i @antv/g2
or try the live demo here https://g2.antv.vision/en/examples/case/pie#pie3type
field and add the payload <img src=x onerror=alert(1)>
An attacker is able to execute malicious JavaScript.