CVE-2026-0858

MEDIUM

Plantuml < 1.2026.0 - XSS

Title source: rule
STIX 2.1

Description

Versions of the package net.sourceforge.plantuml:plantuml before 1.2026.0 are vulnerable to Stored XSS due to insufficient sanitization of interactive attributes in GraphViz diagrams. As a result, a crafted PlantUML diagram can inject malicious JavaScript into generated SVG output, leading to arbitrary script execution in the context of applications that render the SVG.

Scores

CVSS v3 6.1
EPSS 0.0001
EPSS Percentile 3.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-79
Status published
Products (2)
net.sourceforge.plantuml/plantuml 0 - 1.2026.0Maven
plantuml/plantuml < 1.2026.0
Published Jan 16, 2026
Tracked Since Feb 18, 2026