CVE-2026-106139
Received Received - Intake

XSS in Kendo UI for Vue Charts via Unencoded Tooltip

Vulnerability report for CVE-2026-106139, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-10

Last updated on: 2026-10-10

Assigner: Progress Software Corporation

Description

In Progress® Kendo UI for Vue (@progress/kendo-vue-charts) starting with version 2.5.0 and prior to 16.2.0, the default Chart tooltip renders the formatted point value as raw HTML without encoding, in both the single-point and the shared tooltip. An attacker with low privileges who can influence a string value bound to the chart can supply HTML containing event handlers that execute JavaScript in a user's browser when the user hovers over the affected data point. Successful exploitation can compromise the confidentiality and integrity of data accessible to the affected application.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-10
Last Modified
2026-10-10
Generated
2026-10-10
AI Q&A
2026-10-10
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
Progress Software Kendo UI for Vue 2.5.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-80 The product receives input from an upstream component, but it does not neutralize or incorrectly neutralizes special characters such as "<", ">", and "&" that could be interpreted as web-scripting elements when they are sent to a downstream component that processes web pages.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects Progress Kendo UI for Vue chart components. The Chart tooltip in versions 2.5.0 to 16.2.0 renders formatted point values as raw HTML without encoding. An attacker with low privileges can inject HTML containing JavaScript event handlers into chart data. When users hover over the affected data point, the injected script executes in their browser.

Detection Guidance

This vulnerability can be detected by reviewing the version of @progress/kendo-vue-charts in use. Check if the version is between 2.5.0 and 16.2.0. Inspect the application code for Chart components that render tooltips with bound string values.

Impact Analysis

This vulnerability can compromise the confidentiality and integrity of data accessible to the affected application. Attackers could steal sensitive information, manipulate displayed data, or perform actions on behalf of users when they interact with the chart tooltip.

Mitigation Strategies

Upgrade @progress/kendo-vue-charts to version 16.2.0 or later. Review and sanitize any user-controlled data bound to chart tooltips to prevent HTML injection. Implement input validation and output encoding for tooltip content.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-106139. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart