Postorius through 1.3.13 does not escape HTML in the message subject when rendering it in the Held messages pop-up, as exploited in the wild in May 2026.
CVSS Details
- CVSS 3.1 Base Score: 6.1
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade postorius | May 10, 2026 | May 10, 2026 |
| Freebsd | — | Upgrade py312-postoriusUpgrade py310-postoriusUpgrade py313-postoriusUpgrade py314-postoriusUpgrade py311-postoriusUpgrade py315-postorius | May 13, 2026 | May 12, 2026 |
| Ubuntu | — | Upgrade python3-django-postoriusUpgrade python-django-postorius (Ubuntu Pro)Upgrade python3-django-postorius (Ubuntu Pro) | May 28, 2026 | May 27, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub