Remote Code Execution Vulnerability in Evolution Email Client by GNOME
CVE-2026-88859
5.4MEDIUM
What is CVE-2026-88859?
A vulnerability in the Evolution email client allows remote attackers to execute arbitrary JavaScript code. The flaw lies in the handling of specially crafted HTML emails that contain spoofed vCard controls. When users interact with these controls, the email client’s JavaScript handler erroneously sets an attacker-controlled URL to an iframe's source, enabling the execution of malicious scripts that bypass existing safeguards against script execution in email content. This threat underscores the importance of scrutinizing email interactions to protect against potential exploitation.
References
CVSS V3.1
Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Red Hat would like to thank Jurre van Bergen for reporting this issue.