PT-2026-65482 · Pivotick+1 · Pivotick

·

CVE-2026-66919

·

Published

2026-07-28

·

Updated

2026-07-28

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Pivotick (affected versions not specified)
Description A cross-site scripting issue exists in the inspect and edit node modals. Node labels and descriptions from graph data were interpolated directly into the HTML used for modal headers. An attacker capable of supplying or modifying graph data could insert malicious HTML or JavaScript payloads into a node label or description. These payloads are executed in the application origin when a user opens the affected node modals, potentially allowing the attacker to access victim information, modify data, or perform actions using the victim's active session.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-66919

Affected Products

Pivotick