Cross-Site Scripting Vulnerability in Kendo UI for Vue by Progress
CVE-2026-106139
5.4MEDIUM
What is CVE-2026-106139?
Kendo UI for Vue contains a vulnerability where chart tooltips render formatted values as unencoded HTML. This flaw allows an attacker with limited privileges to inject malicious JavaScript into the application. By manipulating the input bound to the chart, an unauthorized user could execute arbitrary scripts in the context of a user's browser, potentially compromising sensitive information. It is crucial for users of the affected versions to apply necessary updates and strengthen their security measures.
Affected Version(s)
Kendo UI for Vue 2.5.0 < 10.1.0