Stored Cross-Site Scripting Vulnerability in DataEase Data Visualization Tool
CVE-2026-32139
What is CVE-2026-32139?
The DataEase data visualization analysis tool, specifically versions 2.10.19 and earlier, contains a vulnerability in the static resource upload interface that permits the uploading of SVG files. The lack of proper validation and sanitization of SVG files allows an attacker to exploit this weakness. While backend checks ensure that the uploaded XML is parseable and has an 'svg' root node, it fails to address the potential for active content embedded within the SVG, such as onload and onerror event handlers. Consequently, this enables attackers to upload malicious SVG files that could execute scripts in browsers when the associated static resource URL is accessed, leading to a complete stored XSS exploitation chain. This issue was addressed in version 2.10.20.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
dataease < 2.10.20
