CVE-2026-27210Active Exploitation(pannellum / pannellum)

MEDIUMCVSS 6.1 · MEDIUM

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch pannellum pannellum systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

Pannellum is a lightweight, free, and open source panorama viewer for the web. In versions 3.5.0 through 2.5.6, the hot spot attributes configuration property allowed any attribute to be set, including HTML event handler attributes, allowing for potential XSS attacks. This affects websites hosting the standalone viewer HTML file and any other use of untrusted JSON config files (bypassing the protections of the escapeHTML parameter). As certain events fire without any additional user interaction, visiting a standalone viewer URL that points to a malicious config file — without additional user interaction — is sufficient to trigger the vulnerability and execute arbitrary JavaScript code, which can, for example, replace the contents of the page with arbitrary content and make it appear to be hosted by the website hosting the standalone viewer HTML file. This issue has been fixed in version 2.5.7. To workaround, setting the Content-Security-Policy header to script-src-attr 'none' will block execution of inline event handlers, mitigating this vulnerability. Don't host pannellum.htm on a domain that shares cookies with user authentication to mitigate XSS risk.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • pannellum

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • General: 1 classified signal
  • Peaked 2d ago at 1 mentions (2026-02-20); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Vendors
Products
pannellum

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-02-20: 1Mentions · 2026-03-24: 1Mentions · 2026-10-07: 1Active Exploitation · 2026-02-20: 1Patch / Workaround · 2026-02-20: 1Technical Details · 2026-02-20: 1Technical Details · 2026-03-24: 102-2003-2410-07
Signal classification2 categories
Active Exploitation
150.0%
General
150.0%
Referenced assets1 URL
By indicator
Classification over time
DateTotalLabels
2026-02-201
Active Exploitation1
2026-03-241
General1
Full discourse3 posts
  • Infoblox@Infoblox
    General

    Dios mio! While researching a particular type of Colombian folk music, we stumbled across a .edu domain selling... accordions? Our first thought was potentially domain hijacking, but it appears to be more likely an exploitation of CVE-2026-27210 (TLDR; cross-site scripting). 🧵 https://t.co/Rt5t1FWbh2

    Post summary

    The tweet points out a potential XSS issue tied to CVE‑2026‑27210 but offers only minimal technical context and no evidence of exploitation or mitigation.

    11030177
    11.3K followersView on X
  • William Entriken@fulldecent

    @petroffm We reviewed this CVE-2026-27210 as a live discussion during our recent Zero Day Live call, where we also tried to reach out to affected vendors and notify them. We also identified It appears most places in the wild already updated :-) Here is our write up https://blog.phor.net/zero-day-pannellum and the podcast episode gets into why/how scam crypto projects were using this for SEO boosts. This collaborative approach to vuln disclosure will be the topic of our team's upcoming talk at JawnCon on 16 Oct. We would love to ask if you have any notes on this approach and would like to cite them in our talk.

    00020299
    6.4K followersView on X
  • Matthew Petroff@petroffm
    Active Exploitation

    Pannellum 2.5.7 has been released, to patch an XSS vulnerability, CVE-2026-27210, primarily affecting the standalone viewer. As the flaw is actively being exploited for cryptocurrency-related phishing, anyone hosting the HTML file is strongly recommended to update immediately.

    Post summary

    Pannellum 2.5.7 releases a patch for CVE-2026-27210, an XSS vulnerability that is actively exploited in cryptocurrency phishing campaigns, urging immediate update.

    0001059
    109 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apppannellumpannellum---

Explore more