Junglewise Threat Intelligence

CVE-2026-55647: DataEase stored XSS in dashboard text components

CVE-2026-55647 · Severity: info · CVSS 5.1 · Published 2026-07-07

Technologies: DataEase. Vendors: DataEase.

Executive brief

DataEase is an open-source tool used for data visualization and business intelligence dashboards. A security flaw allows users with dashboard editing permissions to embed malicious code into text components. When other staff members or external visitors view the affected dashboard, this code executes in their browser, potentially allowing an attacker to steal session information or perform actions on behalf of the victim.

Technical details

A stored Cross-Site Scripting (XSS) vulnerability exists in DataEase dashboard text and scrolling-text components. The root cause is the use of Vue's 'v-html' directive to render 'propValue' content without server-side or client-side HTML sanitization. An authenticated attacker with dashboard editing privileges can inject malicious HTML payloads (e.g., using event handlers like 'onerror' or 'onload') into the component data. These payloads are persisted in the backend database and executed in the context of any user viewing the dashboard, including unauthenticated visitors using shared links. The issue is addressed in version 2.10.24 by implementing proper HTML sanitization before rendering.

Affected products

  • DataEase DataEase < 2.10.24

Timeline

  • 2026-06-18: advisory: GitHub Security Advisory published
  • 2026-07-07: disclosed: CVE published to NVD
  • 2026-07-07: patched: Fix released in version 2.10.24

References

Related threats