Improper Input Validation in ITFlow Email Parser
CVE-2026-97735
8HIGH
What is CVE-2026-97735?
The ITFlow application prior to version 26.08 permits arbitrary SVG file attachments in the ticket email parser. This vulnerability occurs when email messages, sent via SMTP from any source, are processed by the system, allowing potential malicious payloads to be executed. This poses a risk as it opens pathways for attacks leveraging SVG files, which could lead to further exploitation of the application or the server hosting it.
Affected Version(s)
ITFlow 0 < 26.08
