CVE-2026-27210
Last modified
CVE-2026-27210 is a medium-severity vulnerability rated 6.1/10 on the CVSS scale. Pannellum is a lightweight, free, and open source panorama viewer for the web. In versions 3.5.0 through 2.5.6, the hot spot attributes configuration property allowed any attribute to be set, including HTML event handler attributes, allowing for potential XSS attacks. EPSS estimates a 0.32% chance of exploitation in the next 30 days.
Description
Pannellum is a lightweight, free, and open source panorama viewer for the web. In versions 3.5.0 through 2.5.6, the hot spot attributes configuration property allowed any attribute to be set, including HTML event handler attributes, allowing for potential XSS attacks. This affects websites hosting the standalone viewer HTML file and any other use of untrusted JSON config files (bypassing the protections of the escapeHTML parameter). As certain events fire without any additional user interaction, visiting a standalone viewer URL that points to a malicious config file — without additional user interaction — is sufficient to trigger the vulnerability and execute arbitrary JavaScript code, which can, for example, replace the contents of the page with arbitrary content and make it appear to be hosted by the website hosting the standalone viewer HTML file. This issue has been fixed in version 2.5.7. To workaround, setting the Content-Security-Policy header to script-src-attr 'none' will block execution of inline event handlers, mitigating this vulnerability. Don't host pannellum.htm on a domain that shares cookies with user authentication to mitigate XSS risk.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Pannellum | Pannellum | >= 2.5.0, < 2.5.7 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-27210?
How severe is CVE-2026-27210?
How do I fix CVE-2026-27210?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-27203eBay API MCP Server is an open source local MCP server provi…8.3
- CVE-2026-27204Wasmtime is a runtime for WebAssembly. Prior to versions 24.…6.5
- CVE-2026-27205Flask is a web server gateway interface (WSGI) web applicati…4.3
- CVE-2026-27206Zumba Json Serializer is a library to serialize PHP variable…8.1
- CVE-2026-27208bleon-ethical/api-gateway-deploy provides API gateway deploy…7.8
- CVE-2026-2721The MailArchiver plugin for WordPress is vulnerable to Store…4.8
- CVE-2026-27211Cloud Hypervisor is a Virtual Machine Monitor for Cloud work…10
- CVE-2026-27212Swiper is a free and mobile touch slider with hardware accel…7.8
- CVE-2026-27214Substance3D - Painter versions 11.1.2 and earlier are affect…5.5
- CVE-2026-27215Substance3D - Painter versions 11.1.2 and earlier are affect…5.5
- CVE-2026-27216Substance3D - Painter versions 11.1.2 and earlier are affect…5.5
- CVE-2026-27217Substance3D - Painter versions 11.1.2 and earlier are affect…5.5
Are you affected by CVE-2026-27210?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
