Share this

New Highcharts security advisories: What you need to know

Nancy Dillon Avatar

by

2 minutes read

We have published 16 new security advisories affecting Highcharts Core, Dashboards, Grid Lite and Grid Pro.

The vulnerabilities were identified through ongoing security testing and involve several ways that untrusted or user-controlled input can, under specific conditions, bypass protections in our products.

We have released fixes for the identified vulnerabilities. 

Full technical details, including affected versions, patched versions, severity ratings and workarounds where available, can be found in our GitHub Security Advisories.

What Highcharts users should do

We recommend that customers review the advisories relevant to the Highcharts products they use and upgrade to the patched versions. We’ve released fixes across multiple major versions, so you don’t have to jump to the latest major to get them.

npm PackageAffected VersionsPatched versions
highcharts>= 12.0.0, < 12.6.112.6.1
highcharts>= 13.0.0, <= 13.0.213.1.0
highcharts>= 6.1.0, < 11.4.911.4.9
@highcharts/dashboards>= 1.0.0, <= 4.2.14.2.2
@highcharts/grid-lite>= 2.3.0, <= 3.1.03.2.0
@highcharts/grid-pro>= 2.3.0, <= 3.1.03.2.0

Upgrade to your patched version of choice using npm:

If you load from the CDN, use the versioned URLs on code.highcharts.com.

For developers who are unable to upgrade immediately, the individual advisories include workarounds where applicable.

As an additional layer of protection, applications should sanitize untrusted content before passing it to Highcharts, particularly where users or external data sources can influence chart, dashboard or grid configuration or content.

Making our security policy clearer

Security testing continues to evolve, including through increasingly capable AI-assisted testing. These tools are making it possible to uncover combinations and edge cases that were previously difficult to identify.

As testing methods continue to advance, we want our approach to security to evolve with them. In the coming weeks, we will be updating the Highsoft Security Policy to make it clearer and better prepared for the future, with more explicit guidance on Highsoft’s responsibilities around security.

We encourage all Highcharts users to review the new security advisories and upgrade to the patched versions relevant to their implementation.

For questions about your implementation, contact [email protected].

Stay in touch

No spam, just good stuff

We're on discord. Join us for challenges, fun and whatever else we can think of
XSo MeXSo Me Dark
Linkedin So MeLinkedin So Me Dark
Facebook So MeFacebook So Me Dark
Github So MeGithub So Me Dark
Youtube So MeYoutube So Me Dark
Instagram So MeInstagram So Me Dark
Stackoverflow So MeStackoverflow So Me Dark
Discord So MeDiscord So Me Dark

Comments

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.