Impact
Pivotick, a graph visualization library, fails to validate the URL scheme of imagePath values that are derived from graph data before assigning them to SVG image elements. An attacker who can supply crafted graph data can set an imagePath to a malicious URI. When a victim renders the affected graph, the browser resolves the attacker-controlled URI and initiates an unintended request or invokes scheme-specific handling within the victim’s context. Depending on the URI, browser behaviour, and installed protocol handlers, exploitation may disclose limited client or network metadata, enable rendering‑based tracking, or attempt to access local or internal resources.
Affected Systems
The vulnerability affects the Pivotick library. No specific version information is provided in the advisory, so all currently deployed instances of Pivotick that have not applied the patch are potentially impacted.
Risk and Exploitability
The CVSS score of 5.1 indicates moderate risk, and the EPSS score is less than 1%, suggesting a low probability of exploitation in the wild. The vulnerability is not listed in CISA’s KEV catalog. Exploitation requires the attacker to deliver malicious graph data that the victim subsequently loads or renders. The likely attack vector is social engineering or compromised content that injects the vulnerable graph data into a web page. While the impact is limited to unintended client‑side requests and potential data leakage, the absence of a high severity score reflects the need for victim interaction and the limited disclosure surface.
OpenCVE Enrichment