Junglewise Threat Intelligence

CVE-2026-41518: Chartbrew stored DOM XSS in chart legend tooltips

CVE-2026-41518 · Severity: high · CVSS 7.6 · Published 2026-06-04

Vendors: Chartbrew.

Executive brief

Chartbrew is an open-source platform used to create visual dashboards by connecting to databases and APIs. A security flaw allows users with "editor" permissions to embed malicious code into chart legends. When any other person views the resulting dashboard, this code runs automatically in their browser, potentially allowing attackers to steal login tokens, capture keystrokes, or redirect users to fraudulent sites.

Technical details

A stored Cross-Site Scripting (XSS) vulnerability exists in Chartbrew versions 4.9.0 to 5.0.0 due to improper sanitization of the 'ChartDatasetConfig.legend' field. The field is stored as raw text in the Sequelize database and subsequently rendered in the frontend using an unguarded 'innerHTML' assignment within 'ChartTooltip.js'. An authenticated attacker with project-editor privileges can inject a malicious payload that executes automatically when any user (including unauthenticated public viewers) loads a dashboard containing the affected chart. The vulnerability affects Bar, Line, Area, and Matrix charts that share the tooltip rendering logic. A fix is available in version 5.0.1.

Affected products

  • Chartbrew Chartbrew 4.9.0 through 5.0.0

Timeline

  • 2026-05-20: advisory: GitHub Security Advisory published by maintainer
  • 2026-06-04: disclosed: CVE published to NVD
  • 2026-05-20: patched: Version 5.0.1 released with fix

References