CVE-2026-73524: Cypht < 2.12.2 XSS via FROM Email Header in Contacts Module
Cypht before 2.12.2 contains a cross-site scripting vulnerability in the contacts module that allows remote attackers to execute arbitrary script content by embedding malicious payloads within angle brackets in the FROM email header. The sanitization logic removes only the first occurrence of each angle bracket character, leaving additional angle brackets intact, which attackers exploit by delivering a crafted email whose FROM header executes script in the victim's browser when the user opens the message and accesses the Add Local Contacts function.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Cyphtto a version that resolves this vulnerability.Fixed in 2.12.2
Event History
Frequently Asked Questions
Who is exposed to this issue?
Users of Cypht versions before 2.12.2 are exposed if they open an email with a crafted FROM header and then access the Add Local Contacts function. Exploitation requires user interaction.
What does an attacker need to exploit it?
An attacker needs to deliver an email whose FROM header contains a malicious payload using additional angle brackets. No authentication or privileges are required by the attacker.
Are default configurations affected?
The available information identifies the contacts module and the Add Local Contacts function as the affected path, but does not state whether this functionality is enabled or reachable in a default configuration.
What should be done if patching is not immediately possible?
The provided information does not document a workaround. Until upgrading, users should avoid using Add Local Contacts on messages with untrusted or suspicious FROM headers.
How can I determine whether I am affected?
Check the installed Cypht version. Versions before 2.12.2 are affected according to the available information.