Cross-Site Scripting Vulnerability in Pivotick Graph Rendering
CVE-2026-66918
8.2HIGH
What is CVE-2026-66918?
A cross-site scripting vulnerability exists in Pivotick due to inadequate sanitization of user-supplied SVG markup via the per-node style.svgIcon property. This flaw allows attackers to inject executable JavaScript code by manipulating graph data. When a victim interacts with the graph, malicious scripts may execute in the context of the application, enabling unauthorized access to sensitive data, modification of displayed content, or actions performed on behalf of the user. Attackers need to have the ability to control or alter the graph data for successful exploitation.
Affected Version(s)
pivotick 0 <= 1.4.0
