Junglewise Threat Intelligence

CVE-2026-66825: Pivotick cross-site scripting in sidebar property-list

CVE-2026-66825 · Severity: info · CVSS 6.9 · Published 2026-07-27

Technologies: Pivotick. Vendors: Pivotick.

Executive brief

Pivotick, a data visualization and analysis tool, contains a security flaw in how it handles web links within its sidebar. An attacker who can influence the data displayed in the application could insert malicious links that, when clicked by a user, execute unauthorized code. This could allow an attacker to steal sensitive session information or perform actions on behalf of the victim.

Technical details

A stored cross-site scripting (XSS) vulnerability exists in Pivotick's sidebar property-list component. The application fails to validate URL schemes for properties such as 'url', 'href', or 'website', allowing the use of the 'javascript:' pseudo-protocol. An attacker who can supply or influence node or edge property data can inject malicious JavaScript, including variants obfuscated with control characters. When a user clicks the generated link, the script executes in the context of the victim's browser session. The issue is resolved in version 1.4.0 by implementing an allowlist for URL schemes and normalizing property values.

Affected products

  • Pivotick Pivotick < 1.4.0

Timeline

  • 2026-07-27: advisory: CVE-2026-66825 published
  • 2026-07-27: patched: Fix committed to GitHub repository

References

Related threats