{"id":"GHSA-hrvf-g648-rf3m","summary":"PlantUML is vulnerable to Stored XSS due to insufficient sanitization of interactive attributes in GraphViz diagrams","details":"Versions of the package net.sourceforge.plantuml:plantuml before 1.2026.0 are vulnerable to Stored XSS due to insufficient sanitization of interactive attributes in GraphViz diagrams. As a result, a crafted PlantUML diagram can inject malicious JavaScript into generated SVG output, leading to arbitrary script execution in the context of applications that render the SVG.","aliases":["CVE-2026-0858"],"modified":"2026-02-03T03:17:07.638419Z","published":"2026-01-16T06:30:15Z","database_specific":{"nvd_published_at":"2026-01-16T05:16:16Z","cwe_ids":["CWE-79"],"severity":"LOW","github_reviewed":true,"github_reviewed_at":"2026-01-16T20:45:39Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-0858"},{"type":"WEB","url":"https://github.com/plantuml/plantuml/commit/6826315db092d2e432aeab1a0894e08017c6e4bd"},{"type":"PACKAGE","url":"https://github.com/plantuml/plantuml"},{"type":"WEB","url":"https://github.com/plantuml/plantuml/releases/tag/v1.2026.0"},{"type":"WEB","url":"https://security.snyk.io/vuln/SNYK-JAVA-NETSOURCEFORGEPLANTUML-14552230"}],"affected":[{"package":{"name":"net.sourceforge.plantuml:plantuml","ecosystem":"Maven","purl":"pkg:maven/net.sourceforge.plantuml/plantuml"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.2026.0"}]}],"versions":["1.2017.12","1.2017.13","1.2017.14","1.2017.15","1.2017.16","1.2017.18","1.2017.19","1.2017.20","1.2018.0","1.2018.1","1.2018.10","1.2018.11","1.2018.12","1.2018.13","1.2018.14","1.2018.2","1.2018.3","1.2018.4","1.2018.5","1.2018.6","1.2018.7","1.2018.8","1.2018.9","1.2019.0","1.2019.1","1.2019.10","1.2019.11","1.2019.12","1.2019.13","1.2019.2","1.2019.3","1.2019.4","1.2019.5","1.2019.6","1.2019.7","1.2019.8","1.2019.9","1.2020.0","1.2020.1","1.2020.10","1.2020.11","1.2020.12","1.2020.13","1.2020.14","1.2020.15","1.2020.16","1.2020.17","1.2020.18","1.2020.19","1.2020.2","1.2020.20","1.2020.21","1.2020.22","1.2020.23","1.2020.24","1.2020.25","1.2020.26","1.2020.3","1.2020.4","1.2020.6","1.2020.7","1.2020.8","1.2020.9","1.2021.0","1.2021.1","1.2021.10","1.2021.12","1.2021.13","1.2021.14","1.2021.15","1.2021.16","1.2021.2","1.2021.3","1.2021.4","1.2021.5","1.2021.6","1.2021.7","1.2021.8","1.2021.9","1.2022.0","1.2022.1","1.2022.12","1.2022.13","1.2022.14","1.2022.2","1.2022.3","1.2022.4","1.2022.5","1.2022.6","1.2022.7","1.2022.8","1.2023.0","1.2023.1","1.2023.10","1.2023.11","1.2023.12","1.2023.13","1.2023.2","1.2023.4","1.2023.5","1.2023.6","1.2023.7","1.2023.8","1.2023.9","1.2024.1","1.2024.2","1.2024.3","1.2024.4","1.2024.5","1.2024.6","1.2024.7","1.2024.8","1.2025.0","1.2025.10","1.2025.2","1.2025.3","1.2025.4","1.2025.7","1.2025.8","1.2025.9"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/01/GHSA-hrvf-g648-rf3m/GHSA-hrvf-g648-rf3m.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:L/SI:L/SA:N/E:P"}]}