PT-2026-46317 · Chartbrew · Chartbrew

Qiaonpc

·

Published

2026-06-04

·

Updated

2026-06-04

·

CVE-2026-41518

CVSS v3.1

7.6

High

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions Chartbrew versions 4.9.0 through 5.0.0
Description An authenticated user with project-editor permissions can store arbitrary HTML and JavaScript in the ChartDatasetConfig.legend field. This payload is saved in the database and injected into the tooltip DOM element through an unguarded innerHTML assignment in the ChartTooltip.js file. Consequently, any unauthenticated viewer of a public dashboard will trigger the execution of the JavaScript on page load without requiring any interaction. This is a Stored Cross-Site Scripting (XSS) issue, where malicious scripts are permanently stored on the target server and served to other users.
Recommendations Update to version 5.0.1.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2026-41518

Affected Products

Chartbrew