Description
In Progress® KendoReact (@progress/kendo-react-charts) starting with version 1.1.0 and prior to 16.2.0, the default Chart tooltip renders the formatted point value as raw HTML without encoding, in both the single-point and the shared tooltip. An attacker with low privileges who can influence a string value bound to the chart can supply HTML containing event handlers that execute JavaScript in a user's browser when the user hovers over the affected data point. Successful exploitation can compromise the confidentiality and integrity of data accessible to the affected application.
Published: 2026-10-10
Score: 5.4 Medium
EPSS: n/a
KEV: No
Impact: Cross‑Site Scripting leading to data confidentiality and integrity compromise
Action: Apply patch
AI Analysis

Impact

The vulnerability is a classic Cross‑Site Scripting flaw (CWE‑80). In KendoReact chart tooltips the component displays the point value as raw HTML without encoding, both in single‑point and shared tooltips. An attacker with limited privileges who can influence a bound string value can embed arbitrary HTML containing event handlers, which are then executed in a user's browser when they hover over the data point. Successful exploitation can lead to the theft or tampering of application data.

Affected Systems

The affected product is Progress Software's KendoReact (React charting library). Versions starting with 1.1.0 up to, but not including, 16.2.0 are vulnerable. Applications that use the default tooltip configuration of the chart component and receive untrusted data are exposed. The issue applies to any web application that integrates this library.

Risk and Exploitability

The CVSS score of 5.4 indicates moderate risk. No EPSS score is available, so the likelihood of exploitation cannot be quantified from the data. The vulnerability is not currently catalogued in CISA’s KEV. The likely attack vector is client‑side; an attacker must manage to supply a crafted string that is bound to chart data, which can be done via user input, API responses, or injection into a data source. Once the victim hovers over the data point, the embedded script runs, compromising data confidentiality and integrity.

Generated by OpenCVE AI on October 10, 2026 at 10:21 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade KendoReact to 16.2.0 or later, where tooltip content is properly escaped.
  • If an upgrade cannot be applied immediately, disable tooltips for data that originates from untrusted or user‑supplied sources.
  • Sanitize any user‑generated data before binding it to the chart, stripping HTML tags and event attributes that could be injected.
  • Apply a robust Content Security Policy that restricts script execution from inline event handlers—this can reduce the impact of a potential XSS exploitation.

Generated by OpenCVE AI on October 10, 2026 at 10:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 10 Oct 2026 09:30:00 +0000

Type Values Removed Values Added
Description In Progress® KendoReact (@progress/kendo-react-charts) starting with version 1.1.0 and prior to 16.2.0, the default Chart tooltip renders the formatted point value as raw HTML without encoding, in both the single-point and the shared tooltip. An attacker with low privileges who can influence a string value bound to the chart can supply HTML containing event handlers that execute JavaScript in a user's browser when the user hovers over the affected data point. Successful exploitation can compromise the confidentiality and integrity of data accessible to the affected application.
Title Cross-Site Scripting via Chart Tooltip in KendoReact
Weaknesses CWE-80
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: ProgressSoftware

Published:

Updated: 2026-10-10T09:23:05.665Z

Reserved: 2026-10-06T15:51:10.391Z

Link: CVE-2026-106138

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-10T10:16:42.570

Modified: 2026-10-10T10:16:42.570

Link: CVE-2026-106138

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-10T10:30:10Z

Weaknesses
  • CWE-80

    Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)