Open source React executes malicious code with malformed HTML—no authentication needed.