CVE-2026-44311

Source
https://cve.org/CVERecord?id=CVE-2026-44311
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-44311.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-44311
Aliases
Published
2026-06-22T20:50:56Z
Modified
2026-08-12T03:51:41Z
Severity
  • 5.4 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N CVSS Calculator
Summary
Fabric.js: Improper escaping in fabric.Gradient colorStops leads to XSS in SVG serialization
Details

Fabric.js is a Javascript HTML5 canvas library. Prior to 7.4.0, a potential Cross-Site Scripting (XSS) vulnerability exists in Fabric.js due to improper escaping of user-controlled input during SVG serialization via the toSVG() method. Specifically, the color field within the colorStops array of a fabric.Gradient object is not properly escaped when converted into SVG elements. If an application renders the generated SVG string into the DOM, this may allow an attacker to inject arbitrary HTML/SVG and execute JavaScript in the victim's browser. This vulnerability is fixed in 7.4.0.

Database specific
{
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-116",
        "CWE-79"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/44xxx/CVE-2026-44311.json",
    "unresolved_ranges": [
        {
            "extracted_events": [
                {
                    "fixed": "7.4.0"
                }
            ],
            "source": "AFFECTED_FIELD"
        }
    ]
}
References

Affected packages

Git / github.com/fabricjs/fabric.js

Affected ranges

Type
GIT
Repo
https://github.com/fabricjs/fabric.js
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
Show details
{
    "source": "REFERENCES"
}

Affected versions

1.*
1.6.2
1.6.3
1.6.4
1.7.0
1.7.4
2.*
2.4.2-b
3.*
3.3.2
4.*
4.0.0-beta.5
v1.*
v1.2.0
v1.3.0
v1.3.7
v1.4.0
v1.4.10
v1.4.11
v1.4.12
v1.4.13
v1.4.4
v1.4.5
v1.4.6
v1.4.7
v1.4.8
v1.4.9
v1.5.0
v1.6.0
v1.6.1
v1.6.5
v1.6.6
v1.6.7
v1.7.1
v1.7.2
v1.7.3
v1.7.5
v1.7.6
v2.*
v2.0.0
v2.0.0-beta.1
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.6
v2.0.0-beta.7
v2.0.0-rc.1
v2.0.0-rc.2
v2.0.0-rc.3
v2.0.0-rc.4
v2.0.1
v2.0.2
v2.0.3
v2.1.0
v2.2.0
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.1
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.4.0
v2.4.1
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.5.0
v2.6.0
v2.7.0
v3.*
v3.0.0
v3.1.0
v3.2.0
v3.4.0
v3.5.0
v3.6.0
v3.6.1
v4.*
v4.0.0
v4.0.0-beta.1
v4.0.0-beta.10
v4.0.0-beta.11
v4.0.0-beta.12
v4.0.0-beta.2
v4.0.0-beta.3
v4.0.0-beta.4
v4.0.0-beta.6
v4.0.0-beta.7
v4.0.0-beta.8
v4.0.0-beta.9
v4.0.0-rc.1
v4.1.0
v4.2.0
v4.3.0
v4.3.1
v4.4.0
v4.5.0
Other
v451
v460
v500
v510
v610
v620
v630
v640
v641
v642
v643
v650
v651
v652
v653
v654
v660
v661
v662
v700
v700-beta1
v700-rc1
v710
v720
v730
v731
v6.*
v6.0.0-beta1
v6.0.0-beta10
v6.0.0-beta11
v6.0.0-beta12
v6.0.0-beta13
v6.0.0-beta14
v6.0.0-beta15
v6.0.0-beta16
v6.0.0-beta17
v6.0.0-beta18
v6.0.0-beta19
v6.0.0-beta2
v6.0.0-beta20
v6.0.0-beta3
v6.0.0-beta4
v6.0.0-beta5
v6.0.0-beta6
v6.0.0-beta7
v6.0.0-beta8
v6.0.0-beta9
v6.0.0-rc.0
v6.0.0-rc1
v6.0.0-rc2
v6.0.0-rc3
v6.0.0-rc4
v6.0.0-rc5
v6.0.1
v6.0.2

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-44311.json"