Impact
A cross‑site scripting flaw exists in Pivotick’s sidebar property‑list component, where values associated with link‑like properties are rendered as hyperlinks without validating the URL scheme. If an attacker can supply or modify node or edge property data, they may inject a value using the javascript: scheme, or a variant obscured by whitespace or control characters. When a user clicks the resulting link, the browser executes the attacker‑controlled JavaScript in the context of the Pivotick application, enabling the attacker to access information available to the victim’s session or perform actions with the victim’s privileges.
Affected Systems
The vulnerability affects the Pivotick product from Pivotick Inc. No specific version range is provided, but all installations that include the sidebar property‑list component are potentially impacted until the URL normalization fix is applied.
Risk and Exploitability
The CVSS score of 6.9 indicates moderate severity and the EPSS score is < 1%, suggesting a low likelihood of exploitation in practice; the vulnerability is not listed in CISA KEV. Exploitation requires that the attacker be able to influence node or edge property values and that a user click the crafted link, so it is a user‑interaction scenario. Successful exploitation could allow the attacker to inject and execute arbitrary scripts in the victim’s browser session, potentially leading to session hijacking or unauthorized actions within the Pivotick application.
OpenCVE Enrichment