Executive brief
Pivotick, a graph rendering library, contains a security flaw that fails to properly clean data before displaying it. If an attacker can influence the graph data being displayed, they can execute malicious scripts in the browser of a user viewing the graph. This could lead to the theft of sensitive application data, unauthorized actions performed in the user's session, or the modification of displayed information.
Technical details
A Cross-Site Scripting (XSS) vulnerability exists in Pivotick due to improper neutralization of input during web page generation (CWE-79). The vulnerable code in NodeDrawer.ts assigns SVG icon markup from the 'style.svgIcon' property directly to the innerHTML property of a live SVG element without sanitization. An attacker who can control or modify graph data can inject malicious SVG markup containing event handlers, such as an <image> tag with an 'onerror' attribute. When a victim renders the affected graph, the payload executes arbitrary JavaScript in the application's security context. A fix has been identified in a commit that introduces an SvgSanitizer utility to clean the markup before it reaches the DOM.
Affected products
- Pivotick Pivotick <= 1.4.0
Timeline
- 2026-07-28: disclosed
- 2026-07-28: advisory
- 2026-07-28: patched: Fixed in commit 8dbfe4ca3582e715535d261535a0d632ce271dea