Skip to content

Session Hijacking Via Email

High
MrgSub published GHSA-34gh-g567-hq85 Jun 20, 2025

Package

No package listed

Affected versions

0.8

Patched versions

0.81

Description

Summary

Due to improper sanitization it's possible for an attacker to craft an email that executes javascript leading to session hijacking.

Severity

High

CVE ID

CVE-2025-52557

Weaknesses

No CWEs

Credits