A vulnerability described as problematic has been identified in Pivotick up to 1.4.0. Affected by this vulnerability is an unknown functionality of the component Markdown node-reference renderer. Executing a manipulation of the argument nodeName can lead to cross site scripting.
This vulnerability appears as CVE-2026-66921. The attack may be performed from remote. There is no available exploit.
It is best practice to apply a patch to resolve this issue.