Metrics
Affected Vendors & Products
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Fri, 18 Sep 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
M66b
M66b fairemail |
|
| Vendors & Products |
M66b
M66b fairemail |
|
| Metrics |
ssvc
|
Thu, 17 Sep 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | FairEmail is a fully featured, open source, privacy-friendly email app for Android. Prior to 1.2319, the ActivityAMP AMP message renderer in app/src/main/java/eu/faircode/email/ActivityAMP.java enables JavaScript in its WebView but incompletely sanitizes untrusted message HTML. For non-allowlisted hosts, script.removeAttr("src") leaves inline script elements in the document and does not reject event-handler attributes or javascript: URLs on other elements. A crafted AMP email can execute arbitrary JavaScript when a recipient opens the message and enables the AMP toggle. The script can read the message DOM, exfiltrate message data, and display phishing overlays within the message-body area. Exploitation requires the recipient to enable the AMP toggle, and practical exposure is reduced because AMP email is uncommon. This issue is fixed in version 1.2319. | |
| Title | FairEmail: Cross-site scripting (XSS) in AMP message rendering (ActivityAMP) | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-09-18T20:08:14.389Z
Reserved: 2026-06-15T18:40:01.651Z
Link: CVE-2026-54521
Updated: 2026-09-18T20:08:10.223Z
Status : Received
Published: 2026-09-17T21:17:16.397
Modified: 2026-09-18T20:17:16.630
Link: CVE-2026-54521
No data.
OpenCVE Enrichment
Updated: 2026-09-19T02:30:17Z