{"id":31656,"date":"2026-09-29T13:51:40","date_gmt":"2026-09-29T13:51:40","guid":{"rendered":"urn:uuid:d8e90758-5ef2-4a0a-b7e9-a2a0fd05dd63"},"modified":"2026-09-29T13:51:41","modified_gmt":"2026-09-29T13:51:41","slug":"new-highcharts-security-advisories-what-you-need-to-know","status":"publish","type":"post","link":"https:\/\/www.highcharts.com\/blog\/news\/new-highcharts-security-advisories-what-you-need-to-know\/","title":{"rendered":"New Highcharts security advisories: What you need to know"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">We have published <a href=\"https:\/\/github.com\/highcharts\/highcharts\/security\/advisories?page=1\" target=\"_blank\" rel=\"noopener\">16 new security advisories<\/a> affecting Highcharts Core, Dashboards, Grid Lite and Grid Pro.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The vulnerabilities were identified through ongoing security testing and involve several ways that untrusted or user-controlled input can, under specific conditions, bypass protections in our products.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">We have released fixes for the identified vulnerabilities.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Full technical details, including affected versions, patched versions, severity ratings and workarounds where available, can be found in our <a href=\"https:\/\/github.com\/highcharts\/highcharts\/security\/advisories?page=1\" target=\"_blank\" rel=\"noopener\">GitHub Security Advisories<\/a>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>What Highcharts users should do<\/strong><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">We recommend that customers review the advisories relevant to the Highcharts products they use and upgrade to the patched versions. We&#8217;ve released fixes across multiple major versions, so you don&#8217;t have to jump to the latest major to get them.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><tbody><tr><td>npm Package<\/td><td>Affected Versions<\/td><td>Patched versions<\/td><\/tr><tr><td>highcharts<\/td><td>>= 12.0.0, &lt; 12.6.1<\/td><td>12.6.1<\/td><\/tr><tr><td>highcharts<\/td><td>>= 13.0.0, &lt;= 13.0.2<\/td><td>13.1.0<\/td><\/tr><tr><td>highcharts<\/td><td>>= 6.1.0, &lt; 11.4.9<\/td><td>11.4.9<\/td><\/tr><tr><td>@highcharts\/dashboards<\/td><td>>= 1.0.0, &lt;= 4.2.1<\/td><td>4.2.2<\/td><\/tr><tr><td>@highcharts\/grid-lite<\/td><td>>= 2.3.0, &lt;= 3.1.0<\/td><td>3.2.0<\/td><\/tr><tr><td>@highcharts\/grid-pro<\/td><td>>= 2.3.0, &lt;= 3.1.0<\/td><td>3.2.0<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Upgrade to your patched version of choice using npm:<\/p>\n\n\n<div class=\"wp-block-highsoft-hs-ui-code\"><div class=\"hs-ui-code-root\" data-config=\"{&quot;code&quot;:&quot;npm install highcharts@[patched version number]&quot;,&quot;lang&quot;:&quot;bash&quot;,&quot;showLines&quot;:false,&quot;syntax&quot;:true,&quot;diff&quot;:true,&quot;wrap&quot;:true,&quot;copyLabel&quot;:&quot;Copy code&quot;}\"><\/div><noscript><pre class=\"hs-ui-code-fallback\"><code>npm install highcharts@[patched version number]<\/code><\/pre><\/noscript><\/div>\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">If you load from the CDN, use the versioned URLs on code.highcharts.com.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">For developers who are unable to upgrade immediately, the individual advisories include workarounds where applicable.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">As an additional layer of protection, applications should sanitize untrusted content before passing it to Highcharts, particularly where users or external data sources can influence chart, dashboard or grid configuration or content.<br><\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Making our security policy clearer<\/strong><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Security testing continues to evolve, including through increasingly capable AI-assisted testing. These tools are making it possible to uncover combinations and edge cases that were previously difficult to identify.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">As testing methods continue to advance, we want our approach to security to evolve with them. In the coming weeks, we will be updating the Highsoft Security Policy to make it clearer and better prepared for the future, with more explicit guidance on Highsoft\u2019s responsibilities around security.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">We encourage all Highcharts users to review the new security advisories and upgrade to the patched versions relevant to their implementation.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">For questions about your implementation, contact <a href=\"mailto:security@highsoft.com\">security@highsoft.com<\/a>.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>We encourage all Highcharts users to review the new security advisories and upgrade to the patched versions relevant to their implementation.<\/p>\n","protected":false},"author":250,"featured_media":31663,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"meta_title":"Highcharts Security Update: New Security Advisories","meta_description":"Highsoft has published new security advisories for Highcharts products. Learn what\u2019s affected, what users should do, and how we\u2019re strengthening security for the future.","hc_selected_options":[],"footnotes":"","_members_access_role":[],"_members_access_error":""},"categories":[224,211],"tags":[1094,1010,1048],"coauthors":[786],"class_list":["post-31656","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-post","category-news","tag-highcharts-core","tag-highcharts-dashboards","tag-highcharts-grid"],"_links":{"self":[{"href":"https:\/\/www.highcharts.com\/blog\/wp-json\/wp\/v2\/posts\/31656","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.highcharts.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.highcharts.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.highcharts.com\/blog\/wp-json\/wp\/v2\/users\/250"}],"replies":[{"embeddable":true,"href":"https:\/\/www.highcharts.com\/blog\/wp-json\/wp\/v2\/comments?post=31656"}],"version-history":[{"count":5,"href":"https:\/\/www.highcharts.com\/blog\/wp-json\/wp\/v2\/posts\/31656\/revisions"}],"predecessor-version":[{"id":31667,"href":"https:\/\/www.highcharts.com\/blog\/wp-json\/wp\/v2\/posts\/31656\/revisions\/31667"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.highcharts.com\/blog\/wp-json\/wp\/v2\/media\/31663"}],"wp:attachment":[{"href":"https:\/\/www.highcharts.com\/blog\/wp-json\/wp\/v2\/media?parent=31656"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.highcharts.com\/blog\/wp-json\/wp\/v2\/categories?post=31656"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.highcharts.com\/blog\/wp-json\/wp\/v2\/tags?post=31656"},{"taxonomy":"author","embeddable":true,"href":"https:\/\/www.highcharts.com\/blog\/wp-json\/wp\/v2\/coauthors?post=31656"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}