Answer in brief
CVE-2026-106138 records a Medium severity (CVSS 5.4) vulnerability in Cross-Site Scripting via Chart Tooltip in KendoReact. The current sources do not mark it as known exploited. The current feed maps Progress Software/KendoReact (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
CVSS is 5.4. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Progress Software/KendoReact (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Progress Software/KendoReactgeneric | >=1.1.0 <16.2.0 | 16.2.0 |
Published upstream
Oct 10, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Oct 10, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Oct 10, 2026
In Progress® KendoReact (@progress/kendo-react-charts) starting with version 1.1.0 and prior to 16.2.0, the default Chart tooltip renders the formatted point value as raw HTML without encoding, in both the single-point and the shared tooltip. An attacker with low privileges who can influence a string value bound to the chart can supply HTML containing event handlers that execute JavaScript in a user's browser when the user hovers over the affected data point. Successful exploitation can compromise the confidentiality and integrity of data accessible to the affected application.
Quoted source text, attributed separately from HOL analysis.