HTML Sanitization Flaw in Zammad Helpdesk System Exposes User Data
CVE-2026-56735
5.3MEDIUM
What is CVE-2026-56735?
Zammad, an open-source helpdesk and customer support system, has a vulnerability in its HTML sanitizer that allows attackers to embed malicious external URLs in the srcset attribute of tags. Despite blocking external URLs in the standard implementation, the srcset attribute was overlooked, leading to potential exposure of user data, including IP addresses and referral information, when agents interact with affected emails. The issue has been addressed in subsequent releases, specifically versions 7.0.2 and 7.1.0, which enhance the sanitizer to prevent unauthorized external content from compromising user privacy.
Affected Version(s)
zammad < 7.0.2
