Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-45249

28
FAUCET Score

A cross-site scripting (XSS) vulnerability exists in Apache ECharts in the Lines series tooltip rendering logic. This issue affects Apache ECharts: from before 6.1.0. In versions prior to 6.1.0, if both Lines series and tooltip are used, and no user-specified tooltip.formatter is provided, and series.data[i].name is specified, raw HTML string series.data[i].name can be rendered through innerHTML sink into tooltip content. Although tooltip is allowed to accept user-provided raw HTML via a custom tooltip.formatter, the built-in tooltip formatters conventionally perform HTML escaping automatically. This case breaks that convention and may unexpectedly lead to script execution when tooltips are displayed. Users are recommended to upgrade to version 6.1.0 if using the Lines series in this way, which fixes the issue.

First published: May 25, 2026Last modified: May 25, 2026

Impacted Technologies

VendorProductVersion(s)CPE
< 6.1.0CPE matchmatch criteria
cpe:2.3:a:apache:echarts:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

6.1MEDIUM

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
CHANGED
Confidentiality Impact
LOW
Integrity Impact
LOW
Availability Impact
NONE
Exploitability Score
2.8
Impact Score
2.7
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.75%
Probability of exploitation in next 30 days
EPSS Percentile
51.1%
Percentile rank of EPSS score among Peer Group
As of 2026-07-25
Model: v2026.06.15
This CVE's current EPSS score of 0.0075 is in the 58th percentile among its peer group of 26,219 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (3)

github_advisorypatch availablevia nvd_reference
View patch
npmpatch availablevia ghsa
Product: echartsFixed in: 6.1.0
apachevendor investigatingvia vendor_rss
View patch

Vendor Advisories (2)

npmGHSA-fgmj-fm8m-jvvxmedium

Apache ECharts has a cross-site scripting (XSS) vulnerability

May 26, 2026
apacheapache:www.mail-archive.com/[email protected]/msg11134.html

CVE-2026-45249: Apache ECharts: XSS in Lines series tooltip rendering

May 23, 2026

References

openwall.com / lists/oss-security/2026/05/23/4
Mailing ListThird Party Advisory
echarts.apache.org / en/option.html
Product
echarts.apache.org / handbook/en/best-practices/security
Product
github.com / apache/echarts/pull/21608
Issue TrackingPatch
lists.apache.org / thread/1g6xk7gd9vg1c6zyqqt2lnko10zomc3o
Mailing ListVendor Advisory