React's popularity makes React-specific security patterns worth understanding well — the framework itself is secure by default in many ways, but common patterns can undermine that.
Cross-Site Scripting via dangerouslySetInnerHTML
This aptly-named API bypasses React's default XSS protection. Any use of it with user-generated content needs careful sanitization — ideally, avoid it entirely where possible.
Insecure Dependency Chains
The React ecosystem's reliance on npm packages means supply chain vulnerabilities are a real risk. Regular dependency auditing is essential, not optional.
Client-Side Secret Exposure
Environment variables prefixed for client-side access in React apps are bundled into the shipped JavaScript — meaning anything sensitive placed there is effectively public. API keys and secrets belong server-side.
Insufficient Server-Side Validation
Client-side form validation in React improves UX but provides zero actual security — every validation rule must be re-enforced on the server, since client code is always inspectable and bypassable.
Improper JWT Storage
Storing authentication tokens in localStorage exposes them to XSS attacks. HttpOnly cookies, while requiring more setup, offer meaningfully better protection for session tokens.
Cantonet Technologies conducts security reviews specifically for React applications, catching framework-specific patterns that generic security scans often miss.
