DOM-based Cross-Site Scripting Vulnerability in Pivotick by Pivotick
CVE-2026-67174

9.2CRITICAL

Key Information:

Vendor

Pivotick

Status
Vendor
CVE Published:
28 July 2026

What is CVE-2026-67174?

Pivotick is affected by a DOM-based cross-site scripting vulnerability stemming from the improper handling of untrusted data in UI components. Specifically, the tryResolveHTMLElement function incorrectly assigns resolved strings to a element via innerHTML, threatening the integrity of the DOM by allowing arbitrary HTML or SVG content to be executed. This vulnerability exposes various components, including headers and tooltips, to potential JavaScript execution in the context of another user's session. Additionally, the createIcon function integrates caller-supplied SVG icon markup without adequate sanitation, creating another avenue for exploitation. Attackers can leverage crafted data to manipulate application state, gain unauthorized access to user data, and act on behalf of victims. A patch has been implemented to mitigate these risks by enforcing secure rendering practices.

Affected Version(s)

pivotick 0 <= 1.4.0

References

CVSS V4

Score:
9.2
Severity:
CRITICAL
Confidentiality:
High
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Jeroen Pinoy
Sami Mokaddem
.