Sceawere
Vulnerability Detail
CVE-2026-106138UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
KendoReact Chart Stored XSS
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 5.4
- Creation Date
- 2h ago
- Vendor
- Progress Software
- Product
- KendoReact
- Attack Type
- CWE-80 Improper neutralization of Script-Related HTML tags in a web page (basic XSS)
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
In Progress® KendoReact (@progress/kendo-react-charts) starting with version 1.1.0 and prior to 16.2.0, the default Chart tooltip renders the formatted point value as raw HTML without encoding, in both the single-point and the shared tooltip. An attacker with low privileges who can influence a string value bound to the chart can supply HTML containing event handlers that execute JavaScript in a user's browser when the user hovers over the affected data point. Successful exploitation can compromise the confidentiality and integrity of data accessible to the affected application.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "5.4",
"pubDate": "2026-10-10T10:16:42.570Z",
"pubdate": "2026-10-10T10:16:42.570Z",
"executiveSummary": "The Progress KendoReact library (@progress/kendo-react-charts) is susceptible to a Cross-Site Scripting (XSS) vulnerability due to improper input sanitization within the Chart tooltip component.\nThis vulnerability exists in versions 1.1.0 through 16.1.x, affecting both single-point and shared tooltip implementations.\nThe flaw allows a low-privileged attacker, capable of manipulating data bound to the chart, to inject malicious HTML containing JavaScript event handlers.\nWhen a victim user hovers over the manipulated data point, the injected script executes within the context of the user's session, potentially leading to unauthorized data access, session hijacking, or the compromise of application integrity.\nThe vulnerability represents a significant risk to confidentiality and integrity for applications rendering user-controlled chart data without secondary output encoding.\nExploitation requires no special authentication beyond the ability to influence the data source utilized by the chart component.",
"technicalDetails": "The vulnerability originates from the KendoReact Chart component's default rendering mechanism for tooltip content. The library fails to perform output encoding on formatted point values before rendering them as HTML strings in the DOM.\nThe root cause is the lack of context-aware sanitization within the tooltip template engine. When data binding mechanisms feed user-supplied strings into the chart data series, the component treats the input as trusted HTML markup.\nAn attacker can exploit this by injecting malicious HTML payloads—such as '<img src=x onerror=alert(1)>' or elements with 'onmouseover' event handlers—into the data source. Because the library renders this raw string directly, the browser parses the payload as active content.\nThe attack flow follows these steps: 1) The attacker gains the ability to influence the data object bound to the KendoReact Chart (e.g., via a profile update, comment system, or collaborative dashboard). 2) The attacker submits a malicious string payload as a field within the chart's data points. 3) The application server stores this payload in the underlying database. 4) The victim loads the chart in their browser, which fetches the tainted data. 5) The KendoReact Chart component initializes, rendering the tooltip template with the unsanitized malicious string. 6) When the victim triggers the tooltip by hovering over the specific chart data point, the browser executes the injected JavaScript.\nThe vulnerability is present in versions 1.1.0 to 16.1.x of @progress/kendo-react-charts. It affects both standard single-point tooltips and shared tooltips, as both use the same vulnerable rendering logic for data point values.\nBecause the execution occurs in the victim's browser context, the script gains access to the Document Object Model (DOM), browser storage (cookies, localStorage), and the ability to perform requests on behalf of the authenticated user. This post-exploitation impact includes the potential for session token theft, unauthorized administrative actions, or the exfiltration of sensitive application data visible to the victim."
}