PT-2026-98230 · Unknown+1 · Mailspring+3

CVE-2026-93405

·

Published

2026-09-24

·

Updated

2026-09-29

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Mailspring versions prior to 1.17.0
Description The attachment quick preview feature converts Markdown, DOCX, and XLSX attachments using Snarkdown, Mammoth, and SheetJS, then inserts the resulting HTML into the preview document via innerHTML without sanitization. A remote sender can craft a supported attachment that executes scripts when the recipient opens the quick preview. While the preview renderer lacks direct Node or Electron access, injected scripts can reach the IPC (Inter-Process Communication) surface exposed to the quick-preview renderer, allowing script execution within that context.
Recommendations Update to version 1.17.0.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-93405
GHSA-PX2G-JHG5-C6GH

Affected Products

Mailspring
Mammoth
Sheetjs
Snarkdown