Description
The hot spot attributes configuration property allowed any attribute to be set, including HTML event handler attributes, allowing for potential XSS attacks. This affects websites hosting the standalone viewer HTML file and any other use of untrusted JSON config files (bypassing the protections of the escapeHTML parameter).
Recommendation
Update the pannellum package to the latest compatible version. Followings are version details:
- Affected version(s): >= 2.5.0, < 2.5.7
- Patched version(s): 2.5.7
References
Related Issues
- Trix has a Stored XSS vulnerability through serialized attributes - CVE-2026-73426
- NotChatbot WebChat has a stored cross-site scripting (XSS) vulnerability - CVE-2026-30048
- i18nextify has DOM XSS via javascript:/data: URL schemes in translated href/src attributes - CVE-2026-41692
- TinyMCE Cross-Site Scripting (XSS) vulnerability using through data-mce- prefixed src, href, style attributes - CVE-2026-47759
You might also like:
- Tags:
- npm
- pannellum
Anything's wrong? Let us know Last updated on February 23, 2026


