HTML Injection Vulnerability in Mailspring Email Client
CVE-2026-93405
What is CVE-2026-93405?
Mailspring, an open-source email client, has a vulnerability that allows crafted attachments to exploit a lack of sanitization when converting Markdown, DOCX, and XLSX files into HTML for quick preview. When a user opens a malicious attachment, the unchecked HTML can execute scripts, potentially leading to unwanted interactions with the application's inter-process communication (IPC) surface. While the quick preview renderer restricts direct access to Node or Electron, the injection of scripts can still manipulate certain functionalities within the application. This vulnerability is a part of a larger attack vector that includes path traversal and file-writing issues, culminating in a persistent code execution risk. The issue has been addressed in version 1.17.0, and users are advised to update immediately.
Affected Version(s)
Mailspring < 1.17.0
