Cross-Site Scripting Vulnerability in Pivotick by Pivotick
CVE-2026-66825

6.9MEDIUM

Key Information:

Vendor

Pivotick

Status
Vendor
CVE Published:
27 July 2026

What is CVE-2026-66825?

Pivotick contains a vulnerability in the sidebar property-list component that allows for cross-site scripting (XSS) due to insufficient validation of user-supplied links. Attackers could manipulate link properties to inject malicious JavaScript using the javascript: scheme. If users clicked these links, code executed within their browser context could lead to unauthorized access to sensitive information or actions performed on behalf of the user. The issue has been mitigated by normalizing property values and restricting the URL schemes that can be rendered as clickable links.

Affected Version(s)

pivotick 0 < 1.4.0

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Sami Mokaddem
.