Executive brief
billboard.js is a JavaScript charting library used to create interactive data visualizations on websites. The library fails to properly sanitize user input when processing chart configuration options, allowing attackers to inject malicious JavaScript code. If a website uses billboard.js to render charts based on user-supplied data, an attacker could execute arbitrary JavaScript in visitors' browsers, leading to session hijacking, credential theft, or malware distribution.
Technical details
This is a cross-site scripting (XSS) vulnerability (CWE-79) in billboard.js versions before 3.18.0, caused by improper input sanitization during chart option binding. An attacker can inject malicious JavaScript via chart configuration options, which are then executed in the context of the application's webpage without proper HTML escaping or content security measures. The attack requires user interaction (typically clicking or viewing a crafted link containing malicious chart options) but does not require authentication or special network positioning. Successful exploitation allows arbitrary JavaScript execution with the privileges of the logged-in user, potentially leading to account compromise or sensitive data exfiltration. The vulnerability has been patched in version 3.18.0.
Affected products
- NAVER billboard.js before 3.18.0
Timeline
- 2026-01-28: disclosed: Vulnerability published
- 2026-01-28: patched: Fixed in version 3.18.0