🔐 CVE Alert

CVE-2026-73524

MEDIUM 6.1

Cypht < 2.12.2 XSS via FROM Email Header in Contacts Module

CVSS Score
6.1
EPSS Score
0.0%
EPSS Percentile
0th

Cypht before 2.12.2 contains a cross-site scripting vulnerability in the contacts module that allows remote attackers to execute arbitrary script content by embedding malicious payloads within angle brackets in the FROM email header. The sanitization logic removes only the first occurrence of each angle bracket character, leaving additional angle brackets intact, which attackers exploit by delivering a crafted email whose FROM header executes script in the victim's browser when the user opens the message and accesses the Add Local Contacts function.

CWE CWE-79
Vendor cypht-org
Product cypht
Published Sep 1, 2026
Stay Ahead of the Next One

Get instant alerts for cypht-org cypht

Be the first to know when new medium vulnerabilities affecting cypht-org cypht are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Changed
Confidentiality
Low
Integrity
Low
Availability
None

Affected Versions

cypht-org / cypht
0 < 2.12.2

References

NVD ↗ CVE.org ↗ EPSS Data ↗
github.com: https://github.com/cypht-org/cypht/releases/tag/v2.12.2 github.com: https://github.com/cypht-org/cypht/pull/2072 github.com: https://github.com/cypht-org/cypht/commit/372343783b3d21c12f74bb88d0eef36c1579c062 vulncheck.com: https://www.vulncheck.com/advisories/cypht-xss-via-from-email-header-in-contacts-module

Credits

Adam Młynarczyk