Description
TimelineJS renders some user data as HTML. An attacker could implement an XSS exploit with maliciously crafted content in a number of data fields. This risk is present whether the source data for the timeline is stored on Google Sheets or in a JSON configuration file.
Most TimelineJS users configure their timeline with a Google Sheets document.
Recommendation
Update the @knight-lab/timelinejs package to the latest compatible version. Followings are version details:
- Affected version(s): < 3.7.0
- Patched version(s): 3.7.0
References
Could your website be exposed too?
SmartScanner can check your website for Stored XSS in TimelineJS3 and gives you actionable findings to investigate.
Start a free scanRelated Issues
- dbgate-web: Stored XSS in applicationIcon leads to potential RCE in Electron due to unsafe renderer configuration - CVE-2026-34725
- @payloadcms/next has Stored XSS in Admin Panel - CVE-2026-34748
- Cross-site Scripting (XSS) in Eclipse Theia - CVE-2020-27224
- XSS in Vega - CVE-2020-26296


