CVE-2026-73524
Cypht < 2.12.2 XSS via FROM Email Header in Contacts Module
CVSS Score
6.1
EPSS Score
0.0%
EPSS Percentile
0th
Cypht before 2.12.2 contains a cross-site scripting vulnerability in the contacts module that allows remote attackers to execute arbitrary script content by embedding malicious payloads within angle brackets in the FROM email header. The sanitization logic removes only the first occurrence of each angle bracket character, leaving additional angle brackets intact, which attackers exploit by delivering a crafted email whose FROM header executes script in the victim's browser when the user opens the message and accesses the Add Local Contacts function.
| CWE | CWE-79 |
| Vendor | cypht-org |
| Product | cypht |
| Published | Sep 1, 2026 |
Stay Ahead of the Next One
Get instant alerts for cypht-org cypht
Be the first to know when new medium vulnerabilities affecting cypht-org cypht are published — delivered to Slack, Telegram or Discord.
Get Free Alerts →
Free · No credit card · 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Changed
Confidentiality
Low
Integrity
Low
Availability
None
Affected Versions
cypht-org / cypht
0 < 2.12.2
References
github.com: https://github.com/cypht-org/cypht/releases/tag/v2.12.2 github.com: https://github.com/cypht-org/cypht/pull/2072 github.com: https://github.com/cypht-org/cypht/commit/372343783b3d21c12f74bb88d0eef36c1579c062 vulncheck.com: https://www.vulncheck.com/advisories/cypht-xss-via-from-email-header-in-contacts-module
Credits
Adam Młynarczyk