# @iconify/react@6.0.2 security report (npm)

- Verdict: **Needs review** (risk level: medium)
- Scanned: 2026-10-06T14:11:27.000Z
- Files reviewed: 5
- Findings: 2 medium, 6 low severity findings
- Report: https://security.togoder.click/npm/@iconify/react
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package @iconify/react@6.0.2 on Oct 6, 2026. An AI review of 5 source files produced 2 medium, 6 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

## Findings

### [medium] Dynamic code execution via dangerouslySetInnerHTML

Finding ID: `NPS-D0A3FCED089E`

File: `dist/iconify.cjs:1294`

The render function sets componentProps.dangerouslySetInnerHTML.__html from icon body content. While the package attempts to mitigate this with Trusted Types (cleanUpInnerHTML/window.trustedTypes.createPolicy), if Trusted Types is not enforced the raw SVG body from icon data (which can be loaded at runtime from remote API endpoints via loadIcons/fetchAPIModule) is injected as HTML. If an attacker can control icon data (e.g., via a compromised or malicious API provider configured via addAPIProvider or window.IconifyProviders), this could lead to XSS.

### [medium] Dynamic innerHTML assignment

Finding ID: `NPS-842E2820056E`

File: `dist/iconify.js`

The render function uses dangerouslySetInnerHTML to inject SVG body content. While the code includes a cleanUpInnerHTML function that attempts to use Trusted Types policy, this is primarily to satisfy CSP requirements and does not actually sanitize the HTML. If untrusted icon data is passed, this could lead to XSS. The comment explicitly states 'This code doesn't actually clean up anything.'

### [low] Dynamic RegExp construction from icon body content

Finding ID: `NPS-04908E238504`

File: `dist/iconify.cjs:880`

replaceIDs builds a new RegExp from icon-provided id values (escaped) and performs global string replacement on SVG body. While the id is escaped, this pattern of dynamically constructing regexes from data derived from remotely loaded content is a fragile pattern and can be abused for ReDoS or injection if escaping is ever bypassed.

### [low] Network requests to external hosts

Finding ID: `NPS-93DF4F8890BD`

File: `dist/iconify.cjs:1030`

The module performs network fetches to external Iconify API hosts at runtime (https://api.iconify.design, https://api.simplesvg.com, https://api.unisvg.com) using the global fetch. This is expected functionality for icon loading, but it means icon data is retrieved from third-party servers and then rendered into the DOM, expanding the attack surface for supply-chain/remote-content injection.

### [low] Use of window/document global configuration at import time

Finding ID: `NPS-ED5B280136F6`

File: `dist/iconify.cjs:1340`

On import, the module reads window.IconifyPreload and window.IconifyProviders and calls addCollection/addAPIProvider with that attacker-influenceable global data. Combined with the dynamic loading and innerHTML rendering paths, this allows any script that can set those globals to influence which remote servers are contacted and what icon content is rendered.

### [low] External network requests

Finding ID: `NPS-0D8EB23BC59E`

File: `dist/iconify.js`

The code makes network requests to external APIs (api.iconify.design, api.simplesvg.com, api.unisvg.com) to fetch icon data. This is expected functionality for an icon library but could be used for data exfiltration if the icon names or requests contain sensitive information.

### [low] Global object modification

Finding ID: `NPS-7B3369636201`

File: `dist/iconify.js`

The code reads from window.IconifyPreload and window.IconifyProviders and processes them at import time. This allows external code to inject icon collections and API providers, which could be exploited if an attacker can control these global variables.

### [low] Dynamic URL construction

Finding ID: `NPS-703317359300`

File: `dist/iconify.js`

The send function constructs URLs dynamically using prefix and icon names without validation in some paths. This could potentially be used for SSRF or other injection attacks if the inputs are not properly sanitized.

## Files reviewed

- `dist/iconify.cjs` (medium): This is the legitimate Iconify React package; no backdoors, credential harvesting, or process execution were found, but it performs expected remote fetches and renders remotely-loaded SVG via dangerouslySetInnerHTML, which carries XSS/remote-content risk if icon sources are untrusted.
- `dist/iconify.js` (medium): This appears to be a legitimate icon library (Iconify) with expected functionality, but contains a dangerous innerHTML assignment pattern and makes external network requests; the cleanUpInnerHTML function is explicitly noted as not actually sanitizing content.
- `dist/offline.cjs` (safe): No malicious patterns detected; the code is a legitimate Iconify React offline rendering library with only local SVG manipulation and no network, filesystem, process, or dynamic code execution activity.
- `dist/offline.js` (safe): The code is a legitimate Iconify React component library with no malicious patterns such as data exfiltration, credential harvesting, obfuscation, dynamic code execution, or unauthorized network/file system access.
- `vitest.config.ts` (safe): Cleared by Jev triage; no further analysis needed

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
