CVE-2026-59802
PasswordPusher before 2.8.1 accepts data URI schemes in URL push payloads due to insufficient validation in the valid_url function. Attackers can create malicious pushes containing data:text/html URIs that execute arbitrary JavaScript in victims' browsers when clicked, enabling phishing and credential theft under the trusted PasswordPusher domain.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 8.2
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:H/SI:L/SA:N
- EPSS probability
- 0.33%
- CWE
- CWE-183
- Published
- 2026-07-08
- Last modified
- 2026-07-14
Affected products
- PasswordPusher PasswordPusher
- PasswordPusher PasswordPusher
Weakness type
Related vulnerabilities
- CVE-2026-54694 — NationalSecurityAgency/skills-service has Stored XSS via User Registration Enabling Admin Account Takeover
- CVE-2026-55581 — mcp-shell: Secure Mode Allowlist Bypass via Default `/bin/bash` Executable
- CVE-2026-63649 — The Windows interactive service in OpenVPN 2.4.0 through 2.6.21 and 2.7_alpha1 through 2.7.5 allows...
- CVE-2026-67315 — axios 0.31.0 before 0.33.0 and 1.15.0 before 1.18.0 NO_PROXY Bypass via 0.0.0.0
- CVE-2026-67345 — MaxKey 4.1.12 DefaultRedirectResolver OAuth Authorization Code Theft
- CVE-2026-66005 — Jan Local API Server CORS Origin Reflection via 0.0.0.0 Binding
- CVE-2026-16129 — princezuda SafestClaw Built-in Web shell.py ShellAction._validate_command incomplete blacklist
- CVE-2026-46341 — Apify MCP server: Domain Allowlist Bypass in fetch-apify-docs via String Prefix Matching