CVE-2026-66919

Source
https://cve.org/CVERecord?id=CVE-2026-66919
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-66919.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-66919
Published
2026-07-28T12:48:05Z
Modified
2026-08-12T03:51:32Z
Severity
  • 6.9 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
Stored DOM-Based Cross-Site Scripting in Node Modal Headers
Details

Pivotick contains a cross-site scripting vulnerability in the inspect and edit node modals. Node labels and descriptions originating from graph data were interpolated directly into HTML used to construct the modal headers.

An attacker able to supply or modify graph data could insert a malicious HTML or JavaScript payload into a node’s label or description. The payload would be parsed and executed in the application’s origin when a user opened the affected node’s inspect or edit modal.

Successful exploitation could allow the attacker to access information available to the victim, modify application data, or perform actions using the victim’s active session.

The vulnerability has been addressed by creating the modal elements without embedding graph data in HTML and assigning node labels and descriptions through textContent.

Database specific
{
    "cna_assigner": "CIRCL",
    "cwe_ids": [
        "CWE-79"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/66xxx/CVE-2026-66919.json"
}
References

Affected packages

Git / github.com/pivotick/pivotick

Affected ranges

Type
GIT
Repo
https://github.com/pivotick/pivotick
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "last_affected": "1.4.0"
        }
    ],
    "source": [
        "AFFECTED_FIELD",
        "REFERENCES"
    ]
}

Affected versions

v1.*
v1.1.0
v1.2.0
v1.4.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-66919.json"