HTML Injection Vulnerability in Mailspring Email Client
CVE-2026-93405

6.1MEDIUM

Key Information:

Vendor

Foundry376

Vendor
CVE Published:
24 September 2026

What is CVE-2026-93405?

Mailspring, an open-source email client, has a vulnerability that allows crafted attachments to exploit a lack of sanitization when converting Markdown, DOCX, and XLSX files into HTML for quick preview. When a user opens a malicious attachment, the unchecked HTML can execute scripts, potentially leading to unwanted interactions with the application's inter-process communication (IPC) surface. While the quick preview renderer restricts direct access to Node or Electron, the injection of scripts can still manipulate certain functionalities within the application. This vulnerability is a part of a larger attack vector that includes path traversal and file-writing issues, culminating in a persistent code execution risk. The issue has been addressed in version 1.17.0, and users are advised to update immediately.

Affected Version(s)

Mailspring < 1.17.0

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.