PT-2026-46317 · Chartbrew · Chartbrew

·

CVE-2026-41518

·

Published

2026-06-04

·

Updated

2026-06-04

CVSS v3.1

7.6

High

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions Chartbrew versions 4.9.0 through 5.0.0
Description An authenticated user with project-editor permissions can store arbitrary HTML and JavaScript in the ChartDatasetConfig.legend field. This payload is saved in the database and injected into the tooltip DOM element through an unguarded innerHTML assignment in the ChartTooltip.js file. Consequently, any unauthenticated viewer of a public dashboard will trigger the execution of the JavaScript on page load without requiring any interaction. This is a Stored Cross-Site Scripting (XSS) issue, where malicious scripts are permanently stored on the target server and served to other users.
Recommendations Update to version 5.0.1.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-41518
GHSA-6Q2J-365C-7GQF

Affected Products

Chartbrew