CVE-2026-0858

Description

A flaw was found in PlantUML. This vulnerability, known as Stored Cross-Site Scripting (XSS), occurs due to insufficient sanitization of interactive attributes within GraphViz diagrams. A remote attacker can exploit this by crafting a malicious PlantUML diagram, which then injects harmful JavaScript into the generated Scalable Vector Graphics (SVG) output. This can lead to arbitrary script execution within applications that render the affected SVG.

Statement

This vulnerability is rated Moderate for Red Hat. It affects PlantUML versions prior to 1.2026.0, allowing Stored Cross-Site Scripting (XSS) through crafted GraphViz diagrams. When a malicious PlantUML diagram is processed, it can inject arbitrary JavaScript into the generated SVG output, which then executes in the context of applications rendering the SVG. Exploitation requires user interaction with a crafted diagram.

Mitigation

To mitigate this vulnerability, avoid processing or rendering PlantUML diagrams from untrusted sources. If processing untrusted diagrams is unavoidable, ensure that the environment where the SVG output is rendered is adequately sandboxed to limit the impact of potential script execution. This operational control helps reduce exposure to the Stored XSS flaw.

Common Vulnerability Scoring System (CVSS) Score Details

Info alert:Important note

CVSS scores for open source components depend on vendor-specific factors (e.g. version or build chain). Therefore, Red Hat's score and impact rating can be different from NVD and other vendors. Red Hat remains the authoritative CVE Naming Authority (CNA) source for its products and services (see Red Hat classifications).

The following CVSS metrics and score provided are preliminary and subject to review.

CVSS v3 Score Breakdown

Red HatNVDcve.org
Base Score6.1N/AN/A
Attack VectorNetworkN/AN/A
Attack ComplexityLowN/AN/A
Privileges RequiredNoneN/AN/A
User InteractionRequiredN/AN/A
ScopeChangedN/AN/A
ConfidentialityLowN/AN/A
Integrity ImpactLowN/AN/A
Availability ImpactNoneN/AN/A

Vector

Red Hat: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Frequently Asked Questions

Want to get errata notifications? Sign up here.