Cross-Site Scripting Vulnerability in Pivotick by Pivotick
CVE-2026-66825
6.9MEDIUM
What is CVE-2026-66825?
Pivotick contains a vulnerability in the sidebar property-list component that allows for cross-site scripting (XSS) due to insufficient validation of user-supplied links. Attackers could manipulate link properties to inject malicious JavaScript using the javascript: scheme. If users clicked these links, code executed within their browser context could lead to unauthorized access to sensitive information or actions performed on behalf of the user. The issue has been mitigated by normalizing property values and restricting the URL schemes that can be rendered as clickable links.
Affected Version(s)
pivotick 0 < 1.4.0
