Description
The hot spot attributes configuration property allowed any attribute to be set, including HTML event handler attributes, allowing for potential XSS attacks. This affects websites hosting the standalone viewer HTML file and any other use of untrusted JSON config files (bypassing the protections of the escapeHTML parameter).
Recommendation
Update the pannellum package to the latest compatible version. Followings are version details:
- Affected version(s): >= 2.5.0, < 2.5.7
- Patched version(s): 2.5.7
References
Could your website be exposed too?
SmartScanner can check your website for Pannellum has a XSS vulnerability in hot spot attributes and gives you actionable findings to investigate.
Start a free scanRelated Issues
- Trix has a Stored XSS vulnerability through serialized attributes - CVE-2026-73426
- NotChatbot WebChat has a stored cross-site scripting (XSS) vulnerability - CVE-2026-30048
- i18nextify has DOM XSS via javascript:/data: URL schemes in translated href/src attributes - CVE-2026-41692
- TinyMCE Cross-Site Scripting (XSS) vulnerability using through data-mce- prefixed src, href, style attributes - CVE-2026-47759


