Apache ECharts: XSS in Lines series tooltip rendering
Published May 25, 2026
6.1
MEDIUMCVSS 3.1
EPSS 0.93%
Description
A cross-site scripting (XSS) vulnerability exists in Apache ECharts in the Lines series tooltip rendering logic.
This issue affects Apache ECharts: from before 6.1.0.
In versions prior to 6.1.0, if both Lines series and tooltip are used, and no user-specified tooltip.formatter is provided, and series.data[i].name is specified, raw HTML string series.data[i].name can be rendered through innerHTML sink into tooltip content. Although tooltip is allowed to accept user-provided raw HTML via a custom tooltip.formatter, the built-in tooltip formatters conventionally perform HTML escaping automatically. This case breaks that convention and may unexpectedly lead to script execution when tooltips are displayed.
Users are recommended to upgrade to version 6.1.0 if using the Lines series in this way, which fixes the issue.
Affected products
-
Affected
- ≥ 0, < 6.1.0
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Apache Software Foundation | Apache ECharts | unaffected | Affected
|
No data.
No Red Hat product state for this CVE.
echarts
npm
Introduced 0 Fixed 6.1.0
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | echarts | 0 | 6.1.0 |
Remediation
No remediation recorded yet.
References (9)
- http://www.openwall.com/lists/oss-security/2026/05/23/4 Mailing ListThird Party Advisory
- https://echarts.apache.org/en/option.html#series-lines Product
- https://echarts.apache.org/handbook/en/best-practices/security/#passing_raw_html_safely technical-descriptionProduct
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-31650 Advisory
- https://github.com/advisories/GHSA-fgmj-fm8m-jvvx Advisory
- https://github.com/apache/echarts/commit/1e39b00eedda0e4a0b048e099c0e13ce7149d90f
- https://github.com/apache/echarts/pull/21608 patchtechnical-descriptionIssue Tracking
- https://lists.apache.org/thread/1g6xk7gd9vg1c6zyqqt2lnko10zomc3o vendor-advisoryMailing ListVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-45249
| Link | Providers | Tags |
|---|---|---|
| http://www.openwall.com/lists/oss-security/2026/05/23/4 | Mailing ListThird Party Advisory | |
| https://echarts.apache.org/en/option.html#series-lines | Product | |
| https://echarts.apache.org/handbook/en/best-practices/security/#passing_raw_html_safely | technical-descriptionProduct | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-31650 | Advisory | |
| https://github.com/advisories/GHSA-fgmj-fm8m-jvvx | Advisory | |
| https://github.com/apache/echarts/commit/1e39b00eedda0e4a0b048e099c0e13ce7149d90f | ||
| https://github.com/apache/echarts/pull/21608 | patchtechnical-descriptionIssue Tracking | |
| https://lists.apache.org/thread/1g6xk7gd9vg1c6zyqqt2lnko10zomc3o | vendor-advisoryMailing ListVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2026-45249 |
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
Red Hat
No data
GitHub