CVE-2026-73524

Source
https://cve.org/CVERecord?id=CVE-2026-73524
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-73524.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-73524
Published
2026-09-01T20:44:51.262Z
Modified
2026-09-03T03:48:19.004698857Z
Severity
  • 5.1 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N CVSS Calculator
Summary
Cypht < 2.12.2 XSS via FROM Email Header in Contacts Module
Details

Cypht before 2.12.2 contains a cross-site scripting vulnerability in the contacts module that allows remote attackers to execute arbitrary script content by embedding malicious payloads within angle brackets in the FROM email header. The sanitization logic removes only the first occurrence of each angle bracket character, leaving additional angle brackets intact, which attackers exploit by delivering a crafted email whose FROM header executes script in the victim's browser when the user opens the message and accesses the Add Local Contacts function.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/73xxx/CVE-2026-73524.json",
    "cna_assigner": "VulnCheck",
    "cwe_ids": [
        "CWE-79"
    ]
}
References

Affected packages

Git / github.com/cypht-org/cypht

Affected ranges

Type
GIT
Repo
https://github.com/cypht-org/cypht
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Fixed
Database specific
Show details
{
    "source": [
        "DESCRIPTION",
        "REFERENCES"
    ],
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "2.12.2"
        }
    ]
}

Affected versions

v1.*
v1.1.0-rc1
v1.3.0-rc1
v2.*
v2.0.0
v2.0.1
v2.1.0
v2.11.0
v2.12.0
v2.2.0
v2.5.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-73524.json"