Cross-site scripting in highcharts - #VU152789
Published: September 29, 2026
Vulnerability details
The vulnerability allows a remote user to execute arbitrary script in the origin of the page hosting the chart.
The vulnerability exists due to improper neutralization of event-handler attribute names in the breadcrumbs.style option when processing attacker-controlled chart configuration. A remote user can supply event-handler keys under breadcrumbs.style to execute arbitrary script in the origin of the page hosting the chart.
Exploitation requires breadcrumbs to render and a user to hover over or activate a breadcrumb button; charts rendered in styled mode are not affected.