What is CVE-2026-66921?
The vulnerability exists in Pivotick's Markdown node-reference renderer where the attacker-controlled nodeName value is not HTML-escaped before being inserted into the data-node-name attribute and a generated <span> element, potentially leading to XSS attacks. Users should apply the update immediately.
Azərbaycanca: Zəiflik Pivotick-in Markdown node-reference rendererində aşkarlanıb. Təcavüzkarın idarə etdiyi nodeName dəyəri HTML-dən qaçırılmayaraq data-node-name atributu və `<span>` elementinə daxil edilir ki, bu da XSS hücumlarına səbəb ola bilər. İstifadəçilər dərhal yeniləmə tətbiq etməlidir.
Related CVEs
link basis: same weakness class CWE-79; shared vendor: Pivotick
FAQ2
In which component of Pivotick was CVE-2026-66921 discovered?
The vulnerability was discovered in Pivotick's Markdown node-reference renderer.
What type of attack can be carried out by exploiting CVE-2026-66921?
XSS attacks can be carried out.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.