What is CVE-2026-67173?
CVE-2026-67173 is a vulnerability in Pivotick where the URL scheme of node imagePath values from graph data is not validated before being assigned to SVG image resources. An attacker can exploit this by supplying crafted graph data with a malicious URI, potentially causing unintended actions in the victim's browser when the graph is rendered. Affected users should update Pivotick immediately or avoid processing graph data from untrusted sources.
Azərbaycanca: CVE-2026-67173 Pivotick proqramında node imagePath dəyərlərinin URL sxeminin yoxlanılmaması zəifliyidir. Təcavüzkar xüsusi hazırlanmış graph data vasitəsilə zərərli URI təyin edə bilər, bu da qurbanın qrafiki göstərməsi zamanı brauzerdə arzuolunmaz əməliyyatlara səbəb ola bilər. Təsirə məruz qalan istifadəçilərə dərhal Pivotick-i yeniləmək və ya müvəqqəti olaraq etibarsız mənbələrdən gələn graph data-nı emal etməmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-79; shared vendor: Pivotick
FAQ2
Which component of Pivotick is affected by CVE-2026-67173?
The vulnerability is related to the lack of URL scheme validation for node imagePath values from graph data.
How can an attacker exploit CVE-2026-67173?
An attacker can supply crafted graph data with a malicious URI, potentially causing unintended actions in the victim's browser when the graph is rendered.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.