A vulnerability classified as problematic was found in Pivotick up to 1.4.0. Impacted is the function
tryResolveHTMLElement/createIcon of the component UI Element Resolution/Icon Rendering Utilities. Such manipulation leads to cross site scripting.
This vulnerability is traded as CVE-2026-67174. The attack may be launched remotely. There is no exploit available.
It is best practice to apply a patch to resolve this issue.