CVE-2022-25929
MEDIUMsmoothie_charts 1.31.0-1.36.1 - Cross-Site Scripting via strokeStyle and tooltipLabel Properties
Title source: llmDescription
The package smoothie from 1.31.0 and before 1.36.1 are vulnerable to Cross-site Scripting (XSS) due to improper user input sanitization in strokeStyle and tooltipLabel properties. Exploiting this vulnerability is possible when the user can control these properties.
References (5)
Core 5
Core References
Patch, Third Party Advisory
https://github.com/joewalnes/smoothie/commit/8e0920d50da82f4b6e605d56f41b69fbb9606a98
Patch, Third Party Advisory
https://github.com/joewalnes/smoothie/pull/147
Exploit, Third Party Advisory
https://security.snyk.io/vuln/SNYK-JAVA-ORGWEBJARS-3177369
Exploit, Third Party Advisory
https://security.snyk.io/vuln/SNYK-JS-SMOOTHIE-3177364
Scores
CVSS v3
5.4
EPSS
0.0050
EPSS Percentile
66.2%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
partial
Details
CWE
CWE-79
Status
published
Products (2)
npm/smoothie
1.31.0 - 1.36.1npm
smoothiecharts/smoothie_charts
1.31.0 - 1.36.1
Published
Dec 21, 2022
Tracked Since
Feb 18, 2026