Description
In Progress® Kendo UI for Vue (@progress/kendo-vue-charts) starting with version 2.5.0 and prior to 16.2.0, the default Chart tooltip renders the formatted point value as raw HTML without encoding, in both the single-point and the shared tooltip. An attacker with low privileges who can influence a string value bound to the chart can supply HTML containing event handlers that execute JavaScript in a user's browser when the user hovers over the affected data point. Successful exploitation can compromise the confidentiality and integrity of data accessible to the affected application.
Published: 2026-10-10
Score: 5.4 Medium
EPSS: n/a
KEV: No
Impact: Cross-site scripting that permits client‑side script execution
Action: Patch Now
AI Analysis

Impact

The vulnerability originates from the default Kendo UI Chart tooltip, which renders the formatted point value as raw HTML without encoding. An attacker who can influence a string value bound to a chart can supply malicious HTML containing event handlers. When a user hovers over the affected data point, the injected JavaScript runs in the user's browser, exposing or modifying data the application handles. This can lead to confidentiality and integrity compromise of information accessed by the affected application.

Affected Systems

The flaw exists in Progress Software’s Kendo UI for Vue (kendo-vue-charts) component library, affecting all releases from version 2.5.0 up through the last out‑of‑date release before 16.2.0. No other vendors or products are currently listed as impacted.

Risk and Exploitability

The CVSS score of 5.4 indicates moderate severity, and no EPSS data is available, but the issue is exploitable by any attacker who can provide chart data, including low‑privilege users. The vulnerability does not require authentication and can be triggered whenever a user hovers over a chart point, thus posing a potential risk of data theft or session hijack. The flaw is not yet listed in the CISA KEV catalog; however, due to its client‑side nature and the widespread use of the library, it remains a relevant threat.

Generated by OpenCVE AI on October 10, 2026 at 10:20 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update to Kendo UI for Vue version 16.2.0 or later, which encodes tooltip content to prevent XSS.
  • If an upgrade is not yet possible, sanitize all string values that are bound to chart data to remove HTML and event handler attributes before they are passed to the component.
  • As a temporary measure, disable the tooltip feature entirely or configure the chart to suppress tooltips while the vulnerability remains unpatched.

Generated by OpenCVE AI on October 10, 2026 at 10:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 10 Oct 2026 09:30:00 +0000

Type Values Removed Values Added
Description In Progress® Kendo UI for Vue (@progress/kendo-vue-charts) starting with version 2.5.0 and prior to 16.2.0, the default Chart tooltip renders the formatted point value as raw HTML without encoding, in both the single-point and the shared tooltip. An attacker with low privileges who can influence a string value bound to the chart can supply HTML containing event handlers that execute JavaScript in a user's browser when the user hovers over the affected data point. Successful exploitation can compromise the confidentiality and integrity of data accessible to the affected application.
Title Cross-Site Scripting via Chart Tooltip in Kendo UI for Vue
Weaknesses CWE-80
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: ProgressSoftware

Published:

Updated: 2026-10-10T09:23:48.755Z

Reserved: 2026-10-06T15:51:10.391Z

Link: CVE-2026-106139

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-10T10:16:43.933

Modified: 2026-10-10T10:16:43.933

Link: CVE-2026-106139

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-10T10:30:10Z

Weaknesses
  • CWE-80

    Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)