Metrics
Affected Vendors & Products
No advisories yet.
Solution
No solution given by the vendor.
Workaround
To mitigate this issue, users can disable JavaScript execution for HTML mail in Evolution. This can be done through the Evolution preferences or by using `gsettings`. Disabling JavaScript may affect the rendering and functionality of some legitimate HTML emails. To disable JavaScript via `gsettings`, execute the following command: `gsettings set org.gnome.evolution.mail enable-javascript false` To revert this change, execute: `gsettings set org.gnome.evolution.mail enable-javascript true` Note that changes to `gsettings` take effect immediately, but Evolution may need to be restarted for the setting to be fully applied to already open mail views.
Thu, 10 Sep 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
cvssV3_1
|
Thu, 10 Sep 2026 12:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 10 Sep 2026 11:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw was found in Evolution. A remote attacker can exploit this vulnerability by sending a specially crafted HTML email containing a spoofed vCard control. When a victim clicks on this control, Evolution's trusted JavaScript handler incorrectly assigns an attacker-controlled JavaScript URL to an iframe's source. This action leads to arbitrary JavaScript execution within the mail-viewing context, effectively bypassing the security measures designed to prevent script execution in email content. | |
| Title | Evolution: evolution: javascript execution via spoofed vcard control bypasses mail script-markup restriction | |
| First Time appeared |
Redhat
Redhat enterprise Linux |
|
| Weaknesses | CWE-84 | |
| CPEs | cpe:/o:redhat:enterprise_linux:6 cpe:/o:redhat:enterprise_linux:7 cpe:/o:redhat:enterprise_linux:8 cpe:/o:redhat:enterprise_linux:9 |
|
| Vendors & Products |
Redhat
Redhat enterprise Linux |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2026-09-10T15:04:34.399Z
Reserved: 2026-09-10T10:42:51.932Z
Link: CVE-2026-88859
Updated: 2026-09-10T11:37:12.696Z
Status : Awaiting Analysis
Published: 2026-09-10T12:16:33.980
Modified: 2026-09-10T16:18:10.867
Link: CVE-2026-88859
No data.
OpenCVE Enrichment
Updated: 2026-09-10T18:30:09Z