PT-2026-23640 · Chartbrew · Chartbrew

Ytlamal

·

Published

2026-03-06

·

Updated

2026-03-14

·

CVE-2026-27605

CVSS v3.1

6.3

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:U/C:L/I:H/A:N
Name of the Vulnerable Software and Affected Versions Chartbrew versions prior to 4.8.4
Description Chartbrew is a web application that connects to databases and APIs to create charts. Prior to version 4.8.4, the application does not validate file types or content when uploading files, such as project logos. It relies on the file extension provided by the user. These files are saved to the 'uploads/' directory and served statically. An attacker can upload a malicious HTML file containing JavaScript code. Because authentication tokens are likely stored in the browser's local storage, this stored cross-site scripting (XSS) issue could lead to account takeover.
Recommendations Versions prior to 4.8.4 should be updated to version 4.8.4 or later.

Exploit

Fix

Unrestricted File Upload

XSS

Weakness Enumeration

Related Identifiers

CVE-2026-27605
GHSA-JF6M-HM53-C364

Affected Products

Chartbrew