CVE-2026-27210 is a cross-site scripting (XSS) vulnerability affecting Pannellum versions 3.5.0 through 2.5.6, a web-based panorama viewer. The vulnerability arises from improper sanitization of hot spot attributes in configuration files, allowing attackers to inject malicious HTML event handler attributes. With a CVSS score of 6.1 (Medium), this vulnerability can be triggered by a user visiting a specially crafted URL pointing to a malicious configuration file, leading to arbitrary JavaScript execution and potential content manipulation. While no active exploitation or public exploit code has been identified, and community discussion is minimal, organizations are advised to update to version 2.5.7, implement a Content-Security-Policy header with 'script-src-attr 'none'', and avoid hosting pannellum.htm on domains sharing user authentication cookies.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2.5.0, < 2.5.7CPE matchmatch criteria | cpe:2.3:a:pannellum:pannellum:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.