Vulnerabilities/

Pannellum has a XSS vulnerability in hot spot attributes

Severity:
Medium

Description

The hot spot attributes configuration property allowed any attribute to be set, including HTML event handler attributes, allowing for potential XSS attacks. This affects websites hosting the standalone viewer HTML file and any other use of untrusted JSON config files (bypassing the protections of the escapeHTML parameter).

Recommendation

Update the pannellum package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
pannellum
Anything's wrong? Let us know Last updated on February 23, 2026