EUVD-2026-49792
ID: EUVD-2026-49792
Severity: high
CVSS v4: 8.2 (CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N)
CVSS v3: Not provided
CWE: None listed
Source: ENISA
Description
Pivotick fails to sanitize attacker-controlled SVG markup supplied through the per-node style.svgIcon property before inserting it into the document.
When rendering a graph node, the vulnerable code assigns the SVG icon markup directly to the innerHTML property of a live SVG element. An attacker able to influence graph data can provide crafted markup containing executable event handlers, such as an
Timestamps
- Normalized:
- Last updated:
References
No references provided.