{"id":"PYSEC-2026-2891","summary":"Postorius is vulnerable to XSS","details":"Postorius through 1.3.13 does not escape HTML in the message subject when rendering it in the Held messages pop-up, as exploited in the wild in May 2026.","aliases":["CVE-2026-44742","GHSA-r7c9-7pjq-hmm8"],"modified":"2026-07-13T16:32:58.820403307Z","published":"2026-07-13T15:15:40.939562Z","references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-44742"},{"type":"PACKAGE","url":"https://gitlab.com/mailman/postorius"},{"type":"WEB","url":"https://gitlab.com/mailman/postorius/-/commit/c4706abd05ba6bcf472fc674b160d3a9d6a4868b"},{"type":"WEB","url":"https://gitlab.com/mailman/postorius/-/issues/620"},{"type":"WEB","url":"https://gitlab.com/mailman/postorius/-/merge_requests/972"},{"type":"WEB","url":"https://www.openwall.com/lists/oss-security/2026/05/07/3"},{"type":"PACKAGE","url":"https://pypi.org/project/postorius"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-r7c9-7pjq-hmm8"}],"affected":[{"package":{"name":"postorius","ecosystem":"PyPI","purl":"pkg:pypi/postorius"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"1.3.13"}]}],"versions":["1.0.0","1.0.0a1","1.0.0a2","1.0.0b1","1.0.0b2","1.0.0b3","1.0.1","1.0.2","1.0.3","1.1.0","1.1.1","1.1.2","1.2.0","1.2.0a1","1.2.1","1.2.2","1.2.3","1.2.4","1.3.0","1.3.1","1.3.10","1.3.11","1.3.12","1.3.13","1.3.13a1","1.3.2","1.3.3","1.3.3rc1","1.3.3rc2","1.3.4","1.3.4rc1","1.3.5","1.3.6","1.3.6b1","1.3.7","1.3.8","1.3.9"],"database_specific":{"source":"https://github.com/pypa/advisory-database/blob/main/vulns/postorius/PYSEC-2026-2891.yaml"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N"}]}