Article

    Cyber News / Article / Vulnerabilities in DHTMLX software

    Vulnerabilities in DHTMLX software
    CE
    CERT Polska-2026-05-15

    Vulnerabilities in DHTMLX software

    CERT Polska has received a report about vulnerabilities in DHTMLX software and participated in coordination of their disclosure.

    The vulnerabilityCVE-2026-7182: Diagram's export module is vulnerable to Path Traversal insrcattribute due to lack of HTML sanitization. An unauthenticated user could craft the html payload which could include local files from the server and display them in the generated pdf.

    The vulnerabilityCVE-2026-41552: PDF Export Module used in DHTMLX's products Gantt and Scheduler is vulnerable to Path Traversal due to lack of HTML sanitization. An unauthenticated user could craft the html payload which could include local files from the server and display them in the generated PDF.

    The vulnerabilityCVE-2026-41553: PDF Export Module used in DHTMLX's products Gantt and Scheduler is vulnerable to Remote Code Execution due to lack ofdataparameter sanitization. An unauthenticated attacker can inject the malicious JavaScript code to the parameter whose value is processed by Node.js and subsequently executed. This can lead to server compromise.

    Vulnerability CVE-2026-7182 was fixed in Diagram version 1.1.1. Vulnerabilities CVE-2026-41552 and CVE-2026-41553 were fixed in PDF Export Module version 0.7.6.

    We thank Łukasz Jaworski and Tomasz Holeksa from Pentest Limited for the responsible vulnerability report.

    Original source