{"id":"CVE-2026-90529","title":"A vulnerability has been found in DataEase up to 2.10.25/2.10.26","summary":"A vulnerability has been found in DataEase up to 2.10.25/2.10.26. Affected by this issue is the function buildTooltip of the file core/core-frontend/src/views/chart/components/js/panel/charts/map/symbolic-map.ts of the component Symbolic…","severity":"low","cvss":3.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N","cwe":["CWE-79","CWE-94"],"product":"DataEase","affected":["DataEase 2.10.0","DataEase 2.10.1","DataEase 2.10.2","DataEase 2.10.3","DataEase 2.10.4","DataEase 2.10.5","DataEase 2.10.6","DataEase 2.10.7","DataEase 2.10.8","DataEase 2.10.9","DataEase 2.10.10","DataEase 2.10.11","DataEase 2.10.12","DataEase 2.10.13","DataEase 2.10.14","DataEase 2.10.15","DataEase 2.10.16","DataEase 2.10.17","DataEase 2.10.18","DataEase 2.10.19","DataEase 2.10.20","DataEase 2.10.21","DataEase 2.10.22","DataEase 2.10.23","DataEase 2.10.24","DataEase 2.10.25","DataEase 2.10.26"],"published":"2026-09-13","updated":"2026-09-15","sourceUpdated":"2026-09-15T15:17:28.377","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-90529","references":[{"url":"https://github.com/dataease/dataease/","label":"cna@vuldb.com"},{"url":"https://github.com/dataease/dataease/issues/18846","label":"cna@vuldb.com"},{"url":"https://vuldb.com/cve/CVE-2026-90529","label":"cna@vuldb.com"},{"url":"https://vuldb.com/submit/912538","label":"cna@vuldb.com"},{"url":"https://vuldb.com/vuln/403119","label":"cna@vuldb.com"},{"url":"https://vuldb.com/vuln/403119/cti","label":"cna@vuldb.com"}],"tags":["nvd","cve.org"],"epss":0.00199,"epssPercentile":0.09936,"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"partial","timestamp":"2026-09-15T13:35:14.935728Z"},"ingestedAt":"2026-09-14T15:23:07.469Z","slug":"CVE-2026-90529","body":"## Overview\n\nA vulnerability has been found in DataEase up to 2.10.25/2.10.26. Affected by this issue is the function buildTooltip of the file core/core-frontend/src/views/chart/components/js/panel/charts/map/symbolic-map.ts of the component Symbolic Map. Such manipulation of the argument canvasViewInfo[*].customAttr.tooltip.backgroundColor leads to cross site scripting. The attack may be performed from remote. The project was informed of the problem early through an issue report but has not responded yet.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":19,"depthScoreParts":{"impact":19.3,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}