Cross-Site Scripting Vulnerability in Pivotick Graph Rendering
CVE-2026-66918

8.2HIGH

Key Information:

Vendor

Pivotick

Status
Vendor
CVE Published:
28 July 2026

What is CVE-2026-66918?

A cross-site scripting vulnerability exists in Pivotick due to inadequate sanitization of user-supplied SVG markup via the per-node style.svgIcon property. This flaw allows attackers to inject executable JavaScript code by manipulating graph data. When a victim interacts with the graph, malicious scripts may execute in the context of the application, enabling unauthorized access to sensitive data, modification of displayed content, or actions performed on behalf of the user. Attackers need to have the ability to control or alter the graph data for successful exploitation.

Affected Version(s)

pivotick 0 <= 1.4.0

References

CVSS V4

Score:
8.2
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Sami Mokaddem
Jeroen Pinoy
.