Junglewise Threat Intelligence

Highcharts Export Server HTTP resource disclosure

Severity: info · Published 2021-03-12

Vendors: npm.

Executive brief

Highcharts Export Server is a Node.js utility that generates chart images and PDFs from Highcharts JavaScript charts. A vulnerability allows attackers to read files served by internal HTTP services on the same network if they can access the export server, potentially exposing internal web applications, databases, and configuration files. This risk is heightened if the export server is exposed to the internet.

Technical details

The vulnerability is an insecure resource access flaw (CWE-552) that allows an attacker to specify arbitrary internal hostnames or IP addresses to read HTTP-served resources. The root cause is insufficient input validation when the export server processes requests to fetch remote resources. An attacker with network access to the export server can exploit this by crafting requests that target internal services, bypassing network segmentation. The attack requires knowledge of internal hostnames or IP addresses but does not require authentication. Version 2.1.0 and later address this issue, though a major version upgrade is required for full security.

Affected products

  • Highcharts Export Server <=2.0.30

Timeline

  • 2021-03-12: disclosed
  • 2021-03-12: patched: Version 2.1.0 released

References