๐Ÿ” CVE Alert

CVE-2026-93405

MEDIUM 6.1

Mailspring: Stored XSS in attachment quick preview (unsanitized Markdown/DOCX/XLSX conversion)

CVSS Score
6.1
EPSS Score
0.0%
EPSS Percentile
0th

Mailspring is a fast, cross-platform, open-source email client. Prior to 1.17.0, attachment quick preview converts Markdown, DOCX, and XLSX attachments with Snarkdown, Mammoth, and SheetJS and inserts the resulting HTML into the preview document through innerHTML without sanitization. A remote sender can craft a supported attachment whose converted HTML executes script when a recipient opens quick preview. The preview renderer has no direct Node or Electron access, but injected script can reach the IPC surface exposed to the quick-preview renderer. This issue alone provides script execution in the preview renderer; separate path-traversal and renderer-controlled file-write vulnerabilities are required for the documented persistent code-execution chain. This issue is fixed in version 1.17.0.

CWE CWE-79
Vendor foundry376
Product mailspring
Published Sep 24, 2026
Stay Ahead of the Next One

Get instant alerts for foundry376 mailspring

Be the first to know when new medium vulnerabilities affecting foundry376 mailspring are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Changed
Confidentiality
Low
Integrity
Low
Availability
None

Affected Versions

Foundry376 / Mailspring
< 1.17.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/Foundry376/Mailspring/security/advisories/GHSA-px2g-jhg5-c6gh github.com: https://github.com/Foundry376/Mailspring/pull/2523 github.com: https://github.com/Foundry376/Mailspring/commit/5728388199666ec0a9a58f693c89c25b948a9b6c github.com: https://github.com/Foundry376/Mailspring/releases/tag/1.17.0