Description
billboard.js before 3.18.0 allows an attacker to execute malicious JavaScript due to improper sanitization during chart option binding.
Recommendation
Update the billboard.js package to the latest compatible version. Followings are version details:
- Affected version(s): < 3.18.0
- Patched version(s): 3.18.0
References
Related Issues
- Maker.js has Unsafe Property Copying in makerjs.extendObject - CVE-2026-24888
- @digitalocean/do-markdownit has Type Confusion vulnerability - CVE-2025-59717
- Parse Server before v3.4.1 vulnerable to Denial of Service - CVE-2019-1020012
- useragent Regular Expression Denial of Service vulnerability - CVE-2020-26311
- Tags:
- npm
- billboard.js
Anything's wrong? Let us know Last updated on January 28, 2026