CVE-2022-25929

MEDIUM

smoothie_charts 1.31.0-1.36.1 - Cross-Site Scripting via strokeStyle and tooltipLabel Properties

Title source: llm
STIX 2.1

Description

The package smoothie from 1.31.0 and before 1.36.1 are vulnerable to Cross-site Scripting (XSS) due to improper user input sanitization in strokeStyle and tooltipLabel properties. Exploiting this vulnerability is possible when the user can control these properties.

Scores

CVSS v3 5.4
EPSS 0.0050
EPSS Percentile 66.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-79
Status published
Products (2)
npm/smoothie 1.31.0 - 1.36.1npm
smoothiecharts/smoothie_charts 1.31.0 - 1.36.1
Published Dec 21, 2022
Tracked Since Feb 18, 2026