Stored Cross-Site Scripting Vulnerability in DataEase Data Visualization Tool
CVE-2026-32139

5.3MEDIUM

Key Information:

Vendor

Dataease

Status
Vendor
CVE Published:
12 March 2026

What is CVE-2026-32139?

The DataEase data visualization analysis tool, specifically versions 2.10.19 and earlier, contains a vulnerability in the static resource upload interface that permits the uploading of SVG files. The lack of proper validation and sanitization of SVG files allows an attacker to exploit this weakness. While backend checks ensure that the uploaded XML is parseable and has an 'svg' root node, it fails to address the potential for active content embedded within the SVG, such as onload and onerror event handlers. Consequently, this enables attackers to upload malicious SVG files that could execute scripts in browsers when the associated static resource URL is accessed, leading to a complete stored XSS exploitation chain. This issue was addressed in version 2.10.20.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

dataease < 2.10.20

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.