Sceawere

Vulnerability Detail

CVE-2026-106139UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Kendo UI Chart XSS Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.4
Creation Date
2h ago
Vendor
Progress Software
Product
Kendo UI for Vue
Attack Type
CWE-80 Improper neutralization of Script-Related HTML tags in a web page (basic XSS)
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Attack Complexity
LOW

Narrative and Response

Description

In Progress® Kendo UI for Vue (@progress/kendo-vue-charts) starting with version 2.5.0 and prior to 16.2.0, the default Chart tooltip renders the formatted point value as raw HTML without encoding, in both the single-point and the shared tooltip. An attacker with low privileges who can influence a string value bound to the chart can supply HTML containing event handlers that execute JavaScript in a user's browser when the user hovers over the affected data point. Successful exploitation can compromise the confidentiality and integrity of data accessible to the affected application.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.4",
  "pubDate": "2026-10-10T10:16:43.933Z",
  "pubdate": "2026-10-10T10:16:43.933Z",
  "executiveSummary": "A Cross-Site Scripting (XSS) vulnerability exists in @progress/kendo-vue-charts due to improper neutralization of input data within the component's tooltip rendering mechanism.\nThe vulnerability resides in how the Chart tooltip processes and displays formatted point values, rendering them as raw, unencoded HTML.\nAffected products include Progress Kendo UI for Vue, specifically the @progress/kendo-vue-charts package in versions 2.5.0 through 16.1.x.\nAn attacker possessing low-level privileges can manipulate data values bound to the chart to inject malicious HTML payloads, including event handlers like 'onmouseover'.\nUpon a victim user hovering over a compromised data point, the injected JavaScript executes within the context of the user's browser session.\nSuccessful exploitation compromises the confidentiality and integrity of the application, potentially allowing unauthorized access to sensitive data or session hijacking.\nThe attack is mitigated by updating the component to a version where HTML encoding is enforced for tooltip content.",
  "technicalDetails": "The vulnerability is a classic Stored Cross-Site Scripting (XSS) flaw occurring within the tooltip rendering logic of the @progress/kendo-vue-charts component. The root cause is the component's failure to sanitize or encode formatted point values before injecting them into the DOM as inner HTML.\nThe affected components are the single-point and shared tooltip features provided by the library. When a chart is configured to display tooltips, the library automatically processes bound data values to create the tooltip display. In versions 2.5.0 to 16.2.0, this process lacks necessary output encoding, treating any supplied string as markup.\nExploitation requires an attacker to exert influence over the data source or bound properties consumed by the Kendo UI Chart. If the application reflects user-controlled input into these chart data points, an attacker can supply a malicious string containing HTML tags and JavaScript event handlers. For example, a payload crafted as '<img src=x onerror=alert(document.cookie)>' or a div element with an 'onmouseover' handler can be injected into the data field.\nThe attack flow proceeds as follows: First, the attacker identifies a data entry point that populates the Kendo UI Chart, such as a profile field, a dashboard metric, or a report parameter. Second, the attacker submits a payload designed to trigger JavaScript execution upon user interaction. Third, the Kendo UI Chart library consumes this malicious string and renders the tooltip DOM structure without filtering the content. Finally, when an authenticated victim or administrative user hovers over the specific chart data point, the browser interprets the injected HTML. If an event handler is used, the browser immediately executes the attacker-supplied JavaScript within the security context of the application's origin.\nBecause the execution happens in the user's browser, the attacker can perform actions on behalf of the victim, such as stealing session tokens, performing unauthorized API calls, or exfiltrating sensitive data visible in the DOM. This vulnerability does not require administrative privileges, as low-privileged users who can contribute to the chart's dataset can weaponize the component. The impact is significant as it facilitates client-side code execution, effectively bypassing same-origin policy restrictions regarding the data accessible to the user."
}
CVE-2026-106139: Kendo UI Chart XSS Vulnerability (MEDIUM Severity, CVSS: 5.4) | Sceawere