Intel

AIKIDO-2024-10155

echarts is vulnerable to Cross-site Scripting

Cross-site Scripting Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.

60

Medium Risk

This Affects:

jsecharts
2.2.8 - 5.5.0
Fixed in 5.5.1

TL;DR

Affected versions of this package are vulnerable to Cross-site Scripting (XSS) via the tooltip of charts.

Who does this affect?

You are affected if you use a vulnerable version of the package and pass user input to the chart's tooltip (directly or indirectly, such as via a different component).

Background info

echarts is vulnerable to Cross-site Scripting in versions 2.2.8 - 5.5.0.

How to fix this

Upgrade echarts to a patch version.