Official published blog by William Entriken: https://blog.phor.https://blog.phor.net/zero-day-pannellumnet/zero-day-pannellum
During the week I had the pleasure of joining a friend, William Entriken (Fulldecent), for Community Service Hour https://hour.gg/, a livestream reviewing CVE-2026-27210, an XSS vulnerability affecting Pannellum 2.5.6, a panorama viewer used on websites.
Fulldecent walked us through the attack, how it works, and why it matters. To make it interactive, we worked on ways to ethically find affected websites without causing any harm. I thought this was especially neat.
The vulnerability can allow someone to load a remote configuration file through a trusted website and replace the page content while keeping the legitimate domain in the address bar. This has been used against sites including .gov and .edu domains for things like SEO spam and crypto content.
The fix is to update Pannellum to 2.5.7 or later.
I really enjoyed the session, especially the focus on doing security research responsibly and finding ways to help affected sites rather than just demonstrating the vulnerability.
Leave a comment