CVE Explorer
CVE-2026-66825
Pivotick contains a cross-site scripting vulnerability in the sidebar property-list component. Values associated with link-like properties, such as url, uri, href, link, website, or homepage, were rendered as hyperlinks without validating their URL scheme.
An attacker able to supply or influence node or edge property data could provide a malicious value using the javascript: scheme, including variants obfuscated with whitespace or control characters. If a user clicked the generated property lin
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"defaultStatus":"unaffected","product":"pivotick","repo":"https://github.com/Pivotick/Pivotick","vendor":"pivotick","versions":[{"lessThan":"1.4.0","status":"affected","version":"0","versionType":"semver"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:2e1516d61f58c5366a7ac83673061a41e314b3d3d7263bb176fac797b14a4e1c · sha256:6689762f4a1381b5… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","Safety":"NOT_DEFINED","attackComplexity":"LOW","attackRequirements":"NONE","attackVector":"NETWORK","baseScore":6.9,"baseSeverity":"MEDIUM","privilegesRequired":"NONE","providerUrgency":"NOT_DEFINED","subAvailabilityImpact":"NONE","subConfidentialityImpact":"LOW","subIntegrityImpact":"NONE","userInteraction":"NONE","valueDensity":"NOT_DEFINED","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:L/SI:N/SA:N","version":"4.0","vulnAvailabilityImpact":"NONE","vulnConfidentialityImpact":"LOW","vulnIntegrityImpact":"LOW…
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:2e1516d61f58c5366a7ac83673061a41e314b3d3d7263bb176fac797b14a4e1c · sha256:6689762f4a1381b5… · /containers/cna/metrics/0/cvssV4_0
CWE assertions
1 source assertion{"cweId":"CWE-79","description":"CWE-79 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting')","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:2e1516d61f58c5366a7ac83673061a41e314b3d3d7263bb176fac797b14a4e1c · sha256:6689762f4a1381b5… · /containers/cna/problemTypes/0/descriptions/0
Source references
1 source assertion{"tags":["patch"],"url":"https://github.com/Pivotick/Pivotick/commit/84ddc064d53e9e20cce4077d1192bfdb3aecf17b"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:2e1516d61f58c5366a7ac83673061a41e314b3d3d7263bb176fac797b14a4e1c · sha256:6689762f4a1381b5… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.