CVE-2026-0858 MEDIUM

CVE-2026-0858

Vendor N/A
Product net.sourceforge.plantuml:plantuml
Weakness CWE-79 · XSS
Published January 16, 2026
Last update January 16, 2026

CVSS base score

6.1/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction Required
Confidentiality Low
Integrity Low

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N/E:P

What the vulnerability does

01Description

Versions of the package net.sourceforge.plantuml:plantuml before 1.2026.0 are vulnerable to Stored XSS due to insufficient sanitization of interactive attributes in GraphViz diagrams. As a result, a crafted PlantUML diagram can inject malicious JavaScript into generated SVG output, leading to arbitrary script execution in the context of applications that render the SVG.

Key dates

02Disclosure timeline

January 16, 2026 CVE published
January 16, 2026 Record updated