PT-2026-95092 · Fairemail · Fairemail
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
FairEmail versions prior to 1.2319
Description
The ActivityAMP AMP message renderer in
app/src/main/java/eu/faircode/email/ActivityAMP.java enables JavaScript in its WebView but fails to completely sanitize untrusted message HTML. For hosts not on the allowlist, the process of removing the src attribute from script elements leaves inline scripts in the document and fails to reject event-handler attributes or javascript: URLs on other elements. This allows a crafted AMP email to execute arbitrary JavaScript when a recipient opens the message and enables the AMP toggle. The executed script can read the message DOM (Document Object Model), exfiltrate message data, and display phishing overlays within the message-body area.Recommendations
Update to version 1.2319.
As a temporary mitigation, disable the AMP toggle to prevent the execution of arbitrary JavaScript in AMP messages.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Fairemail