{"id":"CVE-2026-106139","title":"In Progress® Kendo UI for Vue (@progress/kendo-vue-charts) starting with version 2.5.0 and prior to 16.2.0, the default Chart tooltip renders the formatted point value as raw HTML without encoding, in both the single-point and the shared…","summary":"In Progress® Kendo UI for Vue (@progress/kendo-vue-charts) starting with version 2.5.0 and prior to 16.2.0, the default Chart tooltip renders the formatted point value as raw HTML without encoding, in both the single-point and the shared…","severity":"medium","cvss":5.4,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","cwe":["CWE-80"],"published":"2026-10-10","updated":"2026-10-10","sourceUpdated":"2026-10-10T10:16:43.933","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-106139","references":[{"url":"https://www.telerik.com/kendo-vue-ui/components/knowledge-base/kb-security-chart-tooltip-xss-cve-2026-1061389","label":"security@progress.com"}],"tags":["nvd"],"ingestedAt":"2026-10-10T10:30:15.300Z","slug":"CVE-2026-106139","body":"## Overview\n\nIn Progress® Kendo UI for Vue (@progress/kendo-vue-charts) starting with version 2.5.0 and prior to 16.2.0, the default Chart tooltip renders the formatted point value as raw HTML without encoding, in both the single-point and the shared tooltip. An attacker with low privileges who can influence a string value bound to the chart can supply HTML containing event handlers that execute JavaScript in a user's browser when the user hovers over the affected data point. Successful exploitation can compromise the confidentiality and integrity of data accessible to the affected application.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":30,"depthScoreParts":{"impact":29.7,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}