CVE-2026-45249Disclosure(apache / echarts)

LOWCVSS 6.1 · MEDIUM

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Patch apache echarts systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A cross-site scripting (XSS) vulnerability exists in Apache ECharts in the Lines series tooltip rendering logic. This issue affects Apache ECharts: from before 6.1.0. In versions prior to 6.1.0, if both Lines series and tooltip are used, and no user-specified tooltip.formatter is provided, and series.data[i].name is specified, raw HTML string series.data[i].name can be rendered through innerHTML sink into tooltip content. Although tooltip is allowed to accept user-provided raw HTML via a custom tooltip.formatter, the built-in tooltip formatters conventionally perform HTML escaping automatically. This case breaks that convention and may unexpectedly lead to script execution when tooltips are displayed. Users are recommended to upgrade to version 6.1.0 if using the Lines series in this way, which fixes the issue.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • echarts

Threat summary

  • Patch or workaround signal is available
  • 6 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 5 signals
  • Disclosure: 4 classified signals
  • General: 1 classified signal
  • Peaked at 3 mentions on most recent observed day (2026-05-26)
  • 6 total mentions across 3 days

Affected systems

Vendors
Products
echarts

Deep dive

Activity timeline6 mentions / 3d
01223Mentions · 2026-05-23: 2Mentions · 2026-05-25: 1Mentions · 2026-05-26: 3Patch / Workaround · 2026-05-26: 2Technical Details · 2026-05-23: 1Technical Details · 2026-05-25: 1Technical Details · 2026-05-26: 305-2305-2505-26
Signal classification3 categories
Disclosure
466.7%
General
116.7%
Patch
116.7%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-05-232
Disclosure1General1
2026-05-251
Disclosure1
2026-05-263
Disclosure2Patch1
Full discourse6 posts
  • Gray Hats@the_yellow_fall
    Disclosure

    Learn about the Apache ECharts XSS vulnerability (CVE-2026-45249) in the Lines series tooltip rendering logic and find out how to secure your code. #Cybersecurity #XSS #ApacheECharts #Infosec #CVE202645249 #WebDev https://securityonline.info/apache-echarts-xss-vulnerability-cve-2026-45249/ https://t.co/hwDkr4kMjc

    Post summary

    The tweet announces the CVE‑2026‑45249 XSS vulnerability in Apache ECharts’ tooltip rendering logic and links to an article that presumably offers remediation guidance.

    04051463
    12.5K followersView on X
  • kokumօtօ@__kokumoto
    Patch

    JavaScriptライブラリのApache EChartsで重要なセキュリティ更新。クロスサイトスクリプティング脆弱性のCVE-2026-45249が修正されている。 https://securityonline.info/apache-echarts-xss-vulnerability-cve-2026-45249/

    Post summary

    The post announces that a security update for Apache ECharts has patched the XSS vulnerability CVE‑2026‑45249.

    010401.1K
    7.6K followersView on X
  • Open Source Security mailing list@oss_security
    Disclosure

    CVE-2026-45249: Apache ECharts: XSS in Lines series tooltip rendering https://www.openwall.com/lists/oss-security/2026/05/23/4 Severity: important

    Post summary

    Apache ECharts XSS vulnerability (CVE‑2026‑45249) was disclosed with an important severity; no PoC, exploit, or patch details are provided, and there is no evidence of active exploitation.

    00050452
    4.7K followersView on X
  • yousukezan@yousukezan
    Disclosure

    Apache EChartsにXSS脆弱性CVE-2026-45249が見つかった。細工データを含むグラフを表示するだけで任意JavaScript実行が可能となり、Webサービスのセッション乗っ取りにつながる恐れがある。 問題はLines系列とTooltip機能の組み合わせに存在する。6.1.0未満では、開発者が独自formatterを設定していない場合、data nameへ埋め込まれたHTMLが適切にエスケープされず、そのままinnerHTML経由で描画される。 通常のTooltip formatterではHTMLエスケープが行われるが、このケースでは安全処理を迂回してしまう。その結果、攻撃者は悪意あるスクリプトをツールチップ内で実行でき、Cookie窃取やアカウント乗っ取りに悪用可能となる。 開発チームは最新版6.1.0で問題を修正済みで、Lines系列を使用している環境には即時更新を推奨している。修正後も既存のグラフカスタマイズ機能には影響しないとされる。 https://securityonline.info/apache-echarts-xss-vulnerability-cve-2026-45249/

    Post summary

    The article discloses a newly found XSS flaw (CVE‑2026‑45249) in Apache ECharts that allows malicious JavaScript execution via crafted data and tooltips, and it recommends upgrading to the patched 6.1.0 release.

    010211.7K
    14.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-45249 A cross-site scripting (XSS) vulnerability exists in Apache ECharts in the Lines series tooltip rendering logic. This issue affects Apache ECharts: from before 6.… https://www.cve.org/CVERecord?id=CVE-2026-45249

    Post summary

    The text reports a cross‑site scripting (XSS) vulnerability (CVE‑2026‑45249) in Apache ECharts’ tooltip rendering logic, referencing the CVE record but not providing any PoC, exploit, patch, or confirmation of active exploitation.

    00000207
    57.5K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-45249 CVE-2026-45249 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-45249

    Post summary

    The post simply references CVE-2026-45249 and links to a vulnerability database page without providing any additional information about the vulnerability.

    0000074
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appapacheecharts---

Explore more