What is CVE-2026-66922?
CVE-2026-66922 involves Pivotick's tree-layout and cycle-detection components mishandling caller-controlled graph node identifiers that match inherited Object.prototype properties like constructor or toString. This could allow prototype pollution or other injection attacks. Pivotick users should immediately apply the security update.
Azərbaycanca: CVE-2026-66922, Pivotick-in ağac düzümü və dövr aşkarlama komponentlərində istifadəçi tərəfindən idarə olunan qrafik düyün identifikatorlarının düzgün işlənməməsi ilə bağlıdır. Bu boşluq `Object.prototype`-dən miras qalan xüsusiyyətlərin (`constructor`, `toString` kimi) manipulyasiyasına yol aça bilər. Pivotick istifadəçiləri təcili olaraq təhlükəsizlik yeniləməsini tətbiq etməlidir.
FAQ1
What is the root cause of the vulnerability described in CVE-2026-66922 in Pivotick?
The vulnerability stems from the tree-layout and cycle-detection components improperly handling caller-controlled graph node identifiers when they match inherited Object.prototype properties like constructor or toString.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.