{"id":"CVE-2026-1513","details":"billboard.js before 3.18.0 allows an attacker to execute malicious JavaScript due to improper sanitization during chart option binding.","aliases":["GHSA-rpc5-pm7q-hjmp"],"modified":"2026-07-09T17:10:54.362080Z","published":"2026-01-28T02:16:00.310Z","related":["openSUSE-SU-2026:10241-1"],"references":[{"type":"ADVISORY","url":"https://cve.naver.com/detail/cve-2026-1513.html"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/naver/billboard.js","events":[{"introduced":"0"},{"fixed":"3abbe9a4e10c02ece62a3cb8e3cf362beceb6099"}],"database_specific":{"cpe":"cpe:2.3:a:naver:billboard.js:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"3.18.0"}],"source":"CPE_RANGE"}}],"versions":["3.17.4","3.17.3","3.17.2","3.17.1","3.17.0","3.16.0","3.15.1","3.15.0","3.14.3","3.14.2","3.14.1","3.14.0","3.13.0","3.12.4","3.12.3","3.12.2","3.12.1","3.12.0","3.11.3","3.11.2","3.11.1","3.11.0","3.10.3","3.10.2","3.10.1","3.10.0","3.9.4","3.9.3","3.9.2","3.9.1","3.8.2","3.8.1","3.8.0","3.7.5","3.7.4","2.2.6","3.7.3","3.7.2","3.7.1","3.7.0","3.6.3","3.6.2","3.6.1","3.6.0","3.5.1","3.5.0","3.4.1","3.4.0","3.3.3","3.3.2","3.3.1","3.3.0","3.2.2","3.2.1","3.2.0","3.1.5","3.1.4","3.1.3","3.1.2","3.1.1","3.1.0","3.0.3","3.0.2","3.0.1","2.2.5","2.2.3","2.2.2","2.2.1","2.2.0","2.1.4","2.1.3","2.1.2","2.1.1","2.1.0","2.0.3","2.0.2","2.0.1","2.0.0","2.0.0-next.8","2.0.0-next.7","2.0.0-next.6","2.0.0-next.5","2.0.0-next.4","2.0.0-next.3","2.0.0-next.2","1.10.1","1.10.0","1.9.5","1.9.4","1.9.3","1.9.2","1.9.1","1.9.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-1513.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"}]}