Cross-site scripting in highcharts - #VU152788
Published: September 29, 2026
Vulnerability details
The vulnerability allows a remote user to execute arbitrary code.
The vulnerability exists due to improper neutralization of input in the HTML text parser when re-rendering a chart from a beforeprint handler in Chromium while printing. A remote user can provide crafted markup in chart configuration to execute arbitrary code.
This affects HTML-rendered text options, including useHTML titles, axis labels, data labels, and text set by responsive rules.