PT-2026-95092 · Fairemail · Fairemail

·

CVE-2026-54521

·

Published

2026-09-17

·

Updated

2026-09-17

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions FairEmail versions prior to 1.2319
Description The ActivityAMP AMP message renderer in app/src/main/java/eu/faircode/email/ActivityAMP.java enables JavaScript in its WebView but fails to completely sanitize untrusted message HTML. For hosts not on the allowlist, the process of removing the src attribute from script elements leaves inline scripts in the document and fails to reject event-handler attributes or javascript: URLs on other elements. This allows a crafted AMP email to execute arbitrary JavaScript when a recipient opens the message and enables the AMP toggle. The executed script can read the message DOM (Document Object Model), exfiltrate message data, and display phishing overlays within the message-body area.
Recommendations Update to version 1.2319. As a temporary mitigation, disable the AMP toggle to prevent the execution of arbitrary JavaScript in AMP messages.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-54521
GHSA-R8FF-QR7G-PVW6

Affected Products

Fairemail