Junglewise Threat Intelligence

CVE-2026-66918: Pivotick XSS in node style.svgIcon property

CVE-2026-66918 · Severity: info · CVSS 8.2 · Published 2026-07-28

Technologies: Pivotick. Vendors: Pivotick.

Executive brief

Pivotick, a graph rendering library, contains a security flaw that fails to properly clean data before displaying it. If an attacker can influence the graph data being displayed, they can execute malicious scripts in the browser of a user viewing the graph. This could lead to the theft of sensitive application data, unauthorized actions performed in the user's session, or the modification of displayed information.

Technical details

A Cross-Site Scripting (XSS) vulnerability exists in Pivotick due to improper neutralization of input during web page generation (CWE-79). The vulnerable code in NodeDrawer.ts assigns SVG icon markup from the 'style.svgIcon' property directly to the innerHTML property of a live SVG element without sanitization. An attacker who can control or modify graph data can inject malicious SVG markup containing event handlers, such as an <image> tag with an 'onerror' attribute. When a victim renders the affected graph, the payload executes arbitrary JavaScript in the application's security context. A fix has been identified in a commit that introduces an SvgSanitizer utility to clean the markup before it reaches the DOM.

Affected products

  • Pivotick Pivotick <= 1.4.0

Timeline

  • 2026-07-28: disclosed
  • 2026-07-28: advisory
  • 2026-07-28: patched: Fixed in commit 8dbfe4ca3582e715535d261535a0d632ce271dea

References

Related threats