CVE-2026-106138
Received Received - Intake

XSS in KendoReact Charts via Unencoded Tooltip

Vulnerability report for CVE-2026-106138, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-10

Last updated on: 2026-10-10

Assigner: Progress Software Corporation

Description

In Progress® KendoReact (@progress/kendo-react-charts) starting with version 1.1.0 and prior to 16.2.0, the default Chart tooltip renders the formatted point value as raw HTML without encoding, in both the single-point and the shared tooltip. An attacker with low privileges who can influence a string value bound to the chart can supply HTML containing event handlers that execute JavaScript in a user's browser when the user hovers over the affected data point. Successful exploitation can compromise the confidentiality and integrity of data accessible to the affected application.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-10
Last Modified
2026-10-10
Generated
2026-10-10
AI Q&A
2026-10-10
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
Progress Software KendoReact 1.1.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-80 The product receives input from an upstream component, but it does not neutralize or incorrectly neutralizes special characters such as "<", ">", and "&" that could be interpreted as web-scripting elements when they are sent to a downstream component that processes web pages.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects Progress KendoReact chart components. The default Chart tooltip renders formatted point values as raw HTML without encoding. An attacker with low privileges can inject HTML containing event handlers that execute JavaScript when a user hovers over a data point. This allows compromise of data confidentiality and integrity in the affected application.

Detection Guidance

This vulnerability is specific to applications using Progress KendoReact Charts versions 1.1.0 to 16.1.9. To detect it, inspect your application's dependencies for @progress/kendo-react-charts versions within this range. Check for tooltip configurations that render unencoded HTML content.

Impact Analysis

If you use Progress KendoReact charts versions 1.1.0 to 16.1.x, an attacker could trick users into hovering over malicious data points to steal sensitive data or perform unauthorized actions. This could lead to data breaches, session hijacking, or malware execution in user browsers.

Compliance Impact

This vulnerability could lead to unauthorized data access or modification, violating GDPR's integrity and confidentiality principles or HIPAA's security requirements for protected health information. Organizations using affected versions may face compliance violations and potential fines.

Mitigation Strategies

Upgrade @progress/kendo-react-charts to version 16.2.0 or later. Review tooltip implementations to ensure HTML content is properly encoded before rendering. Remove any user-controlled input from tooltip bindings if possible.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-106138. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart