Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-w22m-hvvm-xmwx | Fabric.js improper escaping in fabric.Gradient colorStops leads to XSS in SVG serialization |
Tue, 23 Jun 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 23 Jun 2026 01:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Fabricjs
Fabricjs fabric.js |
|
| Vendors & Products |
Fabricjs
Fabricjs fabric.js |
Mon, 22 Jun 2026 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Fabric.js is a Javascript HTML5 canvas library. Prior to 7.4.0, a potential Cross-Site Scripting (XSS) vulnerability exists in Fabric.js due to improper escaping of user-controlled input during SVG serialization via the toSVG() method. Specifically, the color field within the colorStops array of a fabric.Gradient object is not properly escaped when converted into SVG <stop> elements. If an application renders the generated SVG string into the DOM, this may allow an attacker to inject arbitrary HTML/SVG and execute JavaScript in the victim's browser. This vulnerability is fixed in 7.4.0. | |
| Title | Fabric.js: Improper escaping in fabric.Gradient colorStops leads to XSS in SVG serialization | |
| Weaknesses | CWE-116 CWE-79 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-06-23T16:13:58.645Z
Reserved: 2026-05-05T19:00:06.021Z
Link: CVE-2026-44311
Updated: 2026-06-23T16:13:12.706Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-06-23T01:15:16Z
Github GHSA