CVE-2026-26266

Source
https://cve.org/CVERecord?id=CVE-2026-26266
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-26266.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-26266
Aliases
  • GHSA-f65p-p65r-g53q
Published
2026-03-03T22:16:15.387Z
Modified
2026-04-10T05:41:01.597720Z
Severity
  • 9.3 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N CVSS Calculator
Summary
AliasVault affected by Cross-Site Scripting (XSS) via Email HTML Rendering
Details

AliasVault is a privacy-first password manager with built-in email aliasing. A stored cross-site scripting (XSS) vulnerability was identified in the email rendering feature of AliasVault Web Client versions 0.25.3 and lower. When viewing received emails on an alias, the HTML content is rendered in an iframe using srcdoc, which does not provide origin isolation. An attacker can send a crafted email containing malicious JavaScript to any AliasVault email alias. When the victim views the email in the web client, the script executes in the same origin as the application. No sanitization or sandboxing was applied to email HTML content before rendering. This vulnerability is fixed in 0.26.0.[

Database specific
{
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-79"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/26xxx/CVE-2026-26266.json"
}
References

Affected packages

Git / github.com/aliasvault/aliasvault

Affected ranges

Type
GIT
Repo
https://github.com/aliasvault/aliasvault
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-26266.json"