🔐 CVE Alert

CVE-2026-106139

MEDIUM 5.4

Cross-Site Scripting via Chart Tooltip in Kendo UI for Vue

CVSS Score
5.4
EPSS Score
0.0%
EPSS Percentile
0th

In Progress® Kendo UI for Vue (@progress/kendo-vue-charts) starting with version 2.5.0 and prior to 16.2.0, the default Chart tooltip renders the formatted point value as raw HTML without encoding, in both the single-point and the shared tooltip. An attacker with low privileges who can influence a string value bound to the chart can supply HTML containing event handlers that execute JavaScript in a user's browser when the user hovers over the affected data point. Successful exploitation can compromise the confidentiality and integrity of data accessible to the affected application.

CWE CWE-80
Vendor progress software
Product kendo ui for vue
Published Oct 10, 2026
Stay Ahead of the Next One

Get instant alerts for progress software kendo ui for vue

Be the first to know when new medium vulnerabilities affecting progress software kendo ui for vue are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
Required
Scope
Changed
Confidentiality
Low
Integrity
Low
Availability
None

Affected Versions

Progress Software / Kendo UI for Vue
2.5.0 < 10.1.0

References

NVD ↗ CVE.org ↗ EPSS Data ↗
telerik.com: https://www.telerik.com/kendo-vue-ui/components/knowledge-base/kb-security-chart-tooltip-xss-cve-2026-1061389

Credits

Abhishek Nandkumar Bhaskar (Abhi-Hackz)