Junglewise Threat Intelligence

CVE-2026-67174: Pivotick DOM-based XSS in UI element and icon rendering

CVE-2026-67174 · Severity: info · CVSS 9.2 · Published 2026-07-28

Technologies: Pivotick. Vendors: Pivotick.

Executive brief

Pivotick, a data visualization library, contains a security flaw in how it handles user-provided text and icons. An attacker can provide specially crafted data that executes malicious scripts in the browsers of other users viewing the graph. This could lead to unauthorized access to sensitive information, manipulation of data, or actions performed on behalf of the victim.

Technical details

A DOM-based cross-site scripting (XSS) vulnerability exists in Pivotick's 'tryResolveHTMLElement' and 'createIcon' functions. The 'tryResolveHTMLElement' function incorrectly processed strings as HTML by assigning them to a template element's 'innerHTML' property without sanitization. Similarly, 'createIcon' inserted raw SVG markup into the DOM. An unauthenticated attacker can exploit this by providing malicious strings via graph properties, custom rendering callbacks, or SVG icons. This allows for arbitrary JavaScript execution in the context of the victim's session. The vulnerability has been patched by switching to 'textContent' for string rendering and implementing SVG sanitization.

Affected products

  • Pivotick Pivotick <= 1.4.0

Timeline

  • 2026-07-28: disclosed
  • 2026-07-28: patched: Fixed in commit 67c597c
  • 2026-07-28: advisory

References

Related threats