# CVE-2025-52557

## Summary

- **CVE ID:** CVE-2025-52557
- **Severity:** HIGH
- **CVSS Score:** 8.6 (CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N)
- **CWE:** CWE-1384
- **Published:** Jun 21, 2025
- **Last Modified:** Mar 13, 2026

## Description

Mail-0's Zero is an open-source email solution. In version 0.8 it's possible for an attacker to craft an email that executes javascript leading to session hijacking due to improper sanitization. This issue has been patched in version 0.81.

## Affected Products

- Mail-0 — Zero (= 0.8)

## References

- [CNA](https://github.com/Mail-0/Zero/security/advisories/GHSA-34gh-g567-hq85)
- [CNA](https://github.com/Mail-0/Zero/pull/1386)
- [CNA](https://github.com/Mail-0/Zero/commit/48d1df65b62c9c57897b72b241081f447140342f)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.37%
- **EPSS Percentile:** 30.0

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-11._