Uh oh!
There was an error while loading. Please reload this page.
fix(deps): bump echarts to 6.1.0 to patch XSS vulnerability - #5374
Conversation
Fixes GHSA-fgmj-fm8m-jvvx / CVE-2026-45249 — Lines series tooltip rendering could execute raw HTML from series.data[i].name when no custom tooltip.formatter is set.
The latest updates on your projects. Learn more about Vercel for GitHub.
|
PR SummaryLow Risk Overview This addresses a medium-severity XSS (GHSA-fgmj-fm8m-jvvx / CVE-2026-45249) where Lines-series tooltip rendering could inject HTML via Reviewed by Cursor Bugbot for commit e30da31. Configure here. |
Summary
echartsfrom 6.0.0 to 6.1.0, patching a medium-severity XSS in the Lines series tooltip renderer (GHSA-fgmj-fm8m-jvvx / CVE-2026-45249)series.data[i].namecould be rendered as raw HTML into the tooltip viainnerHTMLwhen no customtooltip.formatteris setzrender@6.1.0)Type of Change
Testing
Ran
bun run type-checkandbun run lint— both clean, no code changes required beyond the version bump.Checklist