Bug 2430303 (CVE-2026-0858) - CVE-2026-0858 plantuml: PlantUML: Arbitrary script execution via Stored Cross-Site Scripting in GraphViz diagrams
Summary: CVE-2026-0858 plantuml: PlantUML: Arbitrary script execution via Stored Cross...
Keywords:
Status: NEW
Alias: CVE-2026-0858
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On: 2430307 2430308 2430309 2430310 2430311
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-01-16 06:01 UTC by OSIDB Bzimport
Modified: 2026-01-16 06:13 UTC (History)
0 users

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-01-16 06:01:20 UTC
Versions of the package net.sourceforge.plantuml:plantuml before 1.2026.0 are vulnerable to Stored XSS due to insufficient sanitization of interactive attributes in GraphViz diagrams. As a result, a crafted PlantUML diagram can inject malicious JavaScript into generated SVG output, leading to arbitrary script execution in the context of applications that render the SVG.


Note You need to log in before you can comment on or make changes to this bug.