A vulnerability, which was classified as problematic, has been found in Pivotick up to 1.4.0. This vulnerability affects unknown code of the component SVG Icon Rendering. This manipulation of the argument svgIcon causes cross site scripting.
This vulnerability is handled as CVE-2026-66918. The attack can be initiated remotely. There is not any exploit available.
It is suggested to install a patch to address this issue.