Cross-site scripting in highcharts - #VU152787
Published: September 29, 2026
Vulnerability details
The vulnerability allows a remote user to execute arbitrary script.
The vulnerability exists due to improper neutralization of javascript: URLs in the markup filter for xlink:href attributes when processing markup in text options. A remote user can supply chart configuration containing an SVG anchor with a javascript: xlink:href URL to execute arbitrary script.
Exploitation requires the chart output to be serialized and parsed again and a user to activate the link.