FusionCharts 4.2.3 is now available with an important security dependency update and fixes for legend interactions and Gantt chart task-bar behavior.
Released on September 30, 2026, this update upgrades DOMPurify from version 3.3.3 to 3.4.16 and addresses two issues affecting multi-series stacked charts and Gantt charts.
If you are currently using FusionCharts 4.2.2 or an earlier version, upgrading to 4.2.3 gives you the latest security and stability improvements available in the core FusionCharts package.
Table of Contents
FusionCharts 4.2.3 includes three main updates:
| Update | What changed |
|---|---|
| DOMPurify security update | Upgraded DOMPurify from 3.3.3 to 3.4.16 |
| Multi-series stacked chart fix | Legend hover now highlights the complete series correctly |
| Gantt chart fix | Resolved an error when dragging the final task bar under specific configurations |
Let’s look at each change in more detail.
Upgrading DOMPurify from version 3.3.3 to 3.4.16 is the most important change in FusionCharts 4.2.3.
DOMPurify 3.3.3 is affected by CVE-2026-41238, a prototype-pollution-based cross-site scripting (XSS) bypass affecting DOMPurify versions 3.0.1 through 3.3.3. The vulnerability can affect applications using DOMPurify.sanitize() with the default configuration when a prototype-pollution condition already exists in the same execution context. The issue was fixed in DOMPurify 3.4.0.
FusionCharts 4.2.3 upgrades the bundled DOMPurify dependency to version 3.4.16, incorporating that fix along with subsequent sanitization updates.
DOMPurify is compiled directly into fusioncharts.js. So, updating the dependency in an existing FusionCharts installation will not simply update DOMPurify separately. Applications using the bundled FusionCharts library need to upgrade to FusionCharts 4.2.3 to receive the updated version.
For teams that track frontend dependency security as part of their application security or compliance processes, this is the main reason to prioritize the upgrade.
FusionCharts 4.2.3 also fixes an interaction issue affecting legends in multi-series stacked charts.
Previously, hovering over a legend item could highlight only the first plot belonging to the selected series rather than highlighting the full series.
This could make the interaction confusing in visualizations containing several stacked datasets because the chart did not visually represent the relationship between the legend entry and every relevant plot.
With version 4.2.3, hovering over a legend item correctly highlights the associated series across the chart.
This fix improves visual feedback when users explore complex stacked visualizations through legend interactions.
The release also addresses an issue affecting task-bar interactions in FusionCharts Gantt charts.
Under certain configurations, dragging the last task bar within a Gantt row could result in an error when either:
The issue has been fixed in FusionCharts 4.2.3, allowing the final task bar to be dragged normally in these configurations.
This is particularly relevant for applications that use interactive Gantt charts for project planning, scheduling, resource management, or progress tracking.
FusionCharts 4.2.3 is available through npm, the FusionCharts CDN, downloadable packages, and the FusionCharts GitHub distribution repository.
For npm-based projects, install the release with:
npm install fusioncharts@4.2.3
If FusionCharts is already listed in your project dependencies, review your lockfile after upgrading and run your application’s normal build and test process before deploying the update.
You can also confirm the installed version with:
npm list fusioncharts
The expected version should be:
fusioncharts@4.2.3
Applications that load FusionCharts directly from the CDN can use the versioned 4.2.3 build:
<script src="https://cdn.fusioncharts.com/fusioncharts/4.2.3/fusioncharts.js"></script>
FusionCharts also provides the latest CDN path.
For applications where predictable production deployments are important, using a version-specific URL makes it easier to control when the application moves to a newer FusionCharts release.
The release is available through the usual FusionCharts distribution channels:
Developers who want to review previous releases can also refer to the FusionCharts changelog and package changelog.
If you are currently running FusionCharts 4.2.2, upgrading to 4.2.3 is recommended, particularly because the updated FusionCharts package includes the newer DOMPurify dependency.
The upgrade is also relevant if your application uses:
As with any library upgrade, test the new version in your development or staging environment before rolling it out to production, especially if your application contains custom chart configurations or interactions.
FusionCharts 4.2.3 is a focused maintenance release aimed at improving security and reliability rather than introducing new chart types or APIs.
The update brings the bundled DOMPurify dependency to version 3.4.16 while resolving interaction issues in multi-series stacked charts and Gantt charts.
You can install the latest release through npm or use the versioned FusionCharts 4.2.3 CDN build. For the complete release history, see the FusionCharts changelog.
We released updated FusionCharts SDKs for Angular, Svelte, React Native, and Flutter to support newer…
Quick answer: Creating an interactive React Gantt chart is simple. First, you need to install…
Quick Answer: The best JavaScript map library for data visualization offers a wide range of…
Quick Answer You can add interactive charts to a TypeScript project using a JavaScript charting…
A line chart plots data points along an x-axis (time) and y-axis (value), connected by…
Bar charts, line charts, column charts- they all look similar, but picking the wrong one…