CVE-2026-73524: Cypht < 2.12.2 XSS via FROM Email Header in Contacts Module

Published Sep 1, 2026
·
Updated

Cypht before 2.12.2 contains a cross-site scripting vulnerability in the contacts module that allows remote attackers to execute arbitrary script content by embedding malicious payloads within angle brackets in the FROM email header. The sanitization logic removes only the first occurrence of each angle bracket character, leaving additional angle brackets intact, which attackers exploit by delivering a crafted email whose FROM header executes script in the victim's browser when the user opens the message and accesses the Add Local Contacts function.

Affected Software

1 affected component
Cypht<2.12.2

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Cypht to a version that resolves this vulnerability.

    Fixed in 2.12.2

Event History

Sep 1, 2026
CVE Published
via MITRE·08:44 PM
Data Sourced
via MITRE·08:44 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who is exposed to this issue?

Users of Cypht versions before 2.12.2 are exposed if they open an email with a crafted FROM header and then access the Add Local Contacts function. Exploitation requires user interaction.

2

What does an attacker need to exploit it?

An attacker needs to deliver an email whose FROM header contains a malicious payload using additional angle brackets. No authentication or privileges are required by the attacker.

3

Are default configurations affected?

The available information identifies the contacts module and the Add Local Contacts function as the affected path, but does not state whether this functionality is enabled or reachable in a default configuration.

4

What should be done if patching is not immediately possible?

The provided information does not document a workaround. Until upgrading, users should avoid using Add Local Contacts on messages with untrusted or suspicious FROM headers.

5

How can I determine whether I am affected?

Check the installed Cypht version. Versions before 2.12.2 are affected according to the available information.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203