CVE-2026-106139 - Cross-Site Scripting via Chart Tooltip in Kendo UI for Vue
CVE ID :CVE-2026-106139
Published : Oct. 10, 2026, 10:16 a.m. | 1 hour, 30 minutes ago
Description :In Progress® Kendo UI for Vue (@progress/kendo-vue-charts) starting with version 2.5.0 and prior to 16.2.0, the default Chart tooltip renders the formatted point value as raw HTML without encoding, in both the single-point and the shared tooltip. An attacker with low privileges who can influence a string value bound to the chart can supply HTML containing event handlers that execute JavaScript in a user's browser when the user hovers over the affected data point. Successful exploitation can compromise the confidentiality and integrity of data accessible to the affected application.
Severity: 5.4 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : Oct. 10, 2026, 10:16 a.m. | 1 hour, 30 minutes ago
Description :In Progress® Kendo UI for Vue (@progress/kendo-vue-charts) starting with version 2.5.0 and prior to 16.2.0, the default Chart tooltip renders the formatted point value as raw HTML without encoding, in both the single-point and the shared tooltip. An attacker with low privileges who can influence a string value bound to the chart can supply HTML containing event handlers that execute JavaScript in a user's browser when the user hovers over the affected data point. Successful exploitation can compromise the confidentiality and integrity of data accessible to the affected application.
Severity: 5.4 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...