Ad

CVE-2026-26266

CRITICAL CVSS 3.1: 9.3 EPSS 0.04%
Updated Mar 04, 2026
Aliasvault
Parameter Value
CVSS 9.3 (CRITICAL)
Fixed In 0.26.0
Type CWE-79 (Cross-Site Scripting (XSS))
Vendor Aliasvault
Public PoC No

AliasVault is a privacy-first password manager with built-in email aliasing. A stored cross-site scripting (XSS) vulnerability was identified in the email rendering feature of AliasVault Web Client versions 0.25.3 and lower. When viewing received emails on an alias, the HTML content is rendered in an iframe using srcdoc, which does not provide origin isolation.

An attacker can send a crafted email containing malicious JavaScript to any AliasVault email alias. When the victim views the email in the web client, the script executes in the same origin as the application. No sanitization or sandboxing was applied to email HTML content before rendering.

This vulnerability is fixed in 0.26.0.[

Attack Parameters

Attack Vector
Network
Can be exploited remotely
Attack Complexity
Low
Easy to exploit
Privileges Required
None
No privileges needed
User Interaction
Required
User action required

Impact Assessment

Confidentiality
High
Complete data leak
Integrity
High
Complete data modification
Availability
None
No disruption

CVSS Vector v3.1