Auth0 Lock before 11.21.0 allows XSS when additionalSignUpFields is used with an untrusted placeholder.
https://github.com/CQ-Tools/CVE-2019-20174-fixed
https://github.com/CQ-Tools/CVE-2019-20174-unfixed
https://github.com/advisories/GHSA-w2pf-g6r8-pg22