CVE-2026-93405

Source
https://cve.org/CVERecord?id=CVE-2026-93405
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-93405.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-93405
Aliases
  • GHSA-px2g-jhg5-c6gh
Published
2026-09-24T18:00:32Z
Modified
2026-09-26T03:48:28Z
Severity
  • 6.1 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N CVSS Calculator
Summary
Mailspring: Stored XSS in attachment quick preview (unsanitized Markdown/DOCX/XLSX conversion)
Details

Mailspring is a fast, cross-platform, open-source email client. Prior to 1.17.0, attachment quick preview converts Markdown, DOCX, and XLSX attachments with Snarkdown, Mammoth, and SheetJS and inserts the resulting HTML into the preview document through innerHTML without sanitization. A remote sender can craft a supported attachment whose converted HTML executes script when a recipient opens quick preview. The preview renderer has no direct Node or Electron access, but injected script can reach the IPC surface exposed to the quick-preview renderer. This issue alone provides script execution in the preview renderer; separate path-traversal and renderer-controlled file-write vulnerabilities are required for the documented persistent code-execution chain. This issue is fixed in version 1.17.0.

Database specific
{
    "cna_assigner":  "GitHub_M",
    "cwe_ids":  [
        "CWE-79"
    ],
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/93xxx/CVE-2026-93405.json"
}
References

Affected packages

Git / github.com/foundry376/mailspring

Affected ranges

Type
GIT
Repo
https://github.com/foundry376/mailspring
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Fixed
Database specific
Show details
{
    "extracted_events":  [
        {
            "introduced":  "0"
        },
        {
            "fixed":  "1.17.0"
        }
    ],
    "source":  [
        "AFFECTED_FIELD",
        "REFERENCES"
    ]
}

Affected versions

1.*
1.0.0
1.0.1
1.0.10
1.0.11
1.0.12
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.10.5
1.10.7
1.10.8
1.11.0
1.12.0
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
1.15.0
1.15.1
1.16.0
1.2.0
1.2.1
1.2.2
1.3.0
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.8.0
1.9.0
1.9.1
1.9.2

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-93405.json"