Cyber News / Article / Vulnerabilities in DHTMLX software

Vulnerabilities in DHTMLX software
CERT Polska has received a report about vulnerabilities in DHTMLX software and participated in coordination of their disclosure.
The vulnerabilityCVE-2026-7182: Diagram's export module is vulnerable to Path Traversal insrcattribute due to lack of HTML sanitization. An unauthenticated user could craft the html payload which could include local files from the server and display them in the generated pdf.
The vulnerabilityCVE-2026-41552: PDF Export Module used in DHTMLX's products Gantt and Scheduler is vulnerable to Path Traversal due to lack of HTML sanitization. An unauthenticated user could craft the html payload which could include local files from the server and display them in the generated PDF.
The vulnerabilityCVE-2026-41553: PDF Export Module used in DHTMLX's products Gantt and Scheduler is vulnerable to Remote Code Execution due to lack ofdataparameter sanitization. An unauthenticated attacker can inject the malicious JavaScript code to the parameter whose value is processed by Node.js and subsequently executed. This can lead to server compromise.
Vulnerability CVE-2026-7182 was fixed in Diagram version 1.1.1. Vulnerabilities CVE-2026-41552 and CVE-2026-41553 were fixed in PDF Export Module version 0.7.6.
We thank Åukasz Jaworski and Tomasz Holeksa from Pentest Limited for the responsible vulnerability report.
Related articles
Thomson Reuters Court Software Breach May Have Exposed SSNs and Sealed Data
8 days ago
Fake Software Installers Disable Windows Update and Weaken Microsoft Defender
9 days ago
Massive Microsoft Patch Tuesday September 2026 – 973 Vulnerabilities Fixed, Including 2 Zero-Days
3 days ago
