Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-hrvf-g648-rf3m | PlantUML is vulnerable to Stored XSS due to insufficient sanitization of interactive attributes in GraphViz diagrams |
Mon, 02 Feb 2026 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:plantuml:plantuml:*:*:*:*:*:*:*:* |
Fri, 16 Jan 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Plantuml
Plantuml plantuml |
|
| Vendors & Products |
Plantuml
Plantuml plantuml |
|
| Metrics |
ssvc
|
Fri, 16 Jan 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | plantuml: PlantUML: Arbitrary script execution via Stored Cross-Site Scripting in GraphViz diagrams | |
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Fri, 16 Jan 2026 05:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Versions of the package net.sourceforge.plantuml:plantuml before 1.2026.0 are vulnerable to Stored XSS due to insufficient sanitization of interactive attributes in GraphViz diagrams. As a result, a crafted PlantUML diagram can inject malicious JavaScript into generated SVG output, leading to arbitrary script execution in the context of applications that render the SVG. | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: snyk
Published:
Updated: 2026-01-16T14:10:00.485Z
Reserved: 2026-01-12T09:57:41.760Z
Link: CVE-2026-0858
Updated: 2026-01-16T14:09:56.891Z
Status : Analyzed
Published: 2026-01-16T05:16:16.117
Modified: 2026-04-29T01:00:01.613
Link: CVE-2026-0858
OpenCVE Enrichment
Updated: 2026-04-18T06:00:08Z
Github GHSA