π¨ CVE-2026-93405
Mailspring is a fast, cross-platform, open-source email client. Prior to 1.17.0, attachment quick preview converts Markdown, DOCX, and XLSX attachments with Snarkdown, Mammoth, and SheetJS and inserts the resulting HTML into the preview document through innerHTML without sanitization. A remote sender can craft a supported attachment whose converted HTML executes script when a recipient opens quick preview. The preview renderer has no direct Node or Electron access, but injected script can reach the IPC surface exposed to the quick-preview renderer. This issue alone provides script execution in the preview renderer; separate path-traversal and renderer-controlled file-write vulnerabilities are required for the documented persistent code-execution chain. This issue is fixed in version 1.17.0.
π@cveNotify
Mailspring is a fast, cross-platform, open-source email client. Prior to 1.17.0, attachment quick preview converts Markdown, DOCX, and XLSX attachments with Snarkdown, Mammoth, and SheetJS and inserts the resulting HTML into the preview document through innerHTML without sanitization. A remote sender can craft a supported attachment whose converted HTML executes script when a recipient opens quick preview. The preview renderer has no direct Node or Electron access, but injected script can reach the IPC surface exposed to the quick-preview renderer. This issue alone provides script execution in the preview renderer; separate path-traversal and renderer-controlled file-write vulnerabilities are required for the documented persistent code-execution chain. This issue is fixed in version 1.17.0.
π@cveNotify
GitHub
Add additional safeguards to attachment preview generation (#2523) Β· Foundry376/Mailspring@5728388
* Add security vulnerability assessment for quickpreview attachment chain
Document verified vulnerability chain in quick preview feature:
- XSS via unsanitized HTML from Snarkdown/Mammoth (innerHT...
Document verified vulnerability chain in quick preview feature:
- XSS via unsanitized HTML from Snarkdown/Mammoth (innerHT...
π¨ CVE-2026-95985
The file write tool in Amazon Kiro IDE versions before 1.0.242 might allow remote unauthenticated actors to inject crafted instructions into the agent's context. When a user runs the agent in a crafted repository as an untrusted workspace, sending any message can cause agent modifications to auto-loaded global configuration paths.
We recommend you upgrade to Kiro IDE version 1.0.242 or later. Users who ran the agent in an untrusted workspace on an earlier version should also review the global Kiro configuration directory (~/.kiro) for entries they did not create.
π@cveNotify
The file write tool in Amazon Kiro IDE versions before 1.0.242 might allow remote unauthenticated actors to inject crafted instructions into the agent's context. When a user runs the agent in a crafted repository as an untrusted workspace, sending any message can cause agent modifications to auto-loaded global configuration paths.
We recommend you upgrade to Kiro IDE version 1.0.242 or later. Users who ran the agent in an untrusted workspace on an earlier version should also review the global Kiro configuration directory (~/.kiro) for entries they did not create.
π@cveNotify
π¨ CVE-2026-97232
A vulnerability was determined in volotat Anagnorisis up to 0.4.2. Affected by this vulnerability is the function get_file_content/save_file_content/move_files/start_streaming of the file page.html. This manipulation causes path traversal. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.
π@cveNotify
A vulnerability was determined in volotat Anagnorisis up to 0.4.2. Affected by this vulnerability is the function get_file_content/save_file_content/move_files/start_streaming of the file page.html. This manipulation causes path traversal. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.
π@cveNotify
π¨ CVE-2026-97233
A vulnerability was identified in volotat Anagnorisis up to 0.4.11. Affected by this issue is the function html of the file PlaylistManager.js of the component Media Filename Handler. Such manipulation of the argument file_path leads to cross site scripting. The attack can be launched remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.
π@cveNotify
A vulnerability was identified in volotat Anagnorisis up to 0.4.11. Affected by this issue is the function html of the file PlaylistManager.js of the component Media Filename Handler. Such manipulation of the argument file_path leads to cross site scripting. The attack can be launched remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.
π@cveNotify
π¨ CVE-2026-81161
Privilege Defined With Unsafe Actions vulnerability in Drupal Content Moderation Notifications allows Privilege Escalation. This issue affects Content Moderation Notifications versions: from 0.0.0 to 3.9.0.
π@cveNotify
Privilege Defined With Unsafe Actions vulnerability in Drupal Content Moderation Notifications allows Privilege Escalation. This issue affects Content Moderation Notifications versions: from 0.0.0 to 3.9.0.
π@cveNotify
Drupal.org
Content Moderation Notifications - Moderately critical - Access bypass - SA-CONTRIB-2026-107
The module provides a permission that allows users to configure email templates containing Twig code. This permission was not marked as restricted. A site administrator might inadvertently grant this permission to less-trusted users. This would allow thoseβ¦
π¨ CVE-2026-69280
Use after free in Windows Push Notifications allows an authorized attacker to elevate privileges locally.
π@cveNotify
Use after free in Windows Push Notifications allows an authorized attacker to elevate privileges locally.
π@cveNotify
π¨ CVE-2026-69283
Heap-based buffer overflow in Windows CD-ROM Driver allows an authorized attacker to elevate privileges locally.
π@cveNotify
Heap-based buffer overflow in Windows CD-ROM Driver allows an authorized attacker to elevate privileges locally.
π@cveNotify
π¨ CVE-2026-69289
Improper link resolution before file access ('link following') in Windows Setup Files Cleanup allows an authorized attacker to elevate privileges locally.
π@cveNotify
Improper link resolution before file access ('link following') in Windows Setup Files Cleanup allows an authorized attacker to elevate privileges locally.
π@cveNotify
π¨ CVE-2026-69290
Stack-based buffer overflow in Windows Storage Spaces Controller allows an authorized attacker to elevate privileges locally.
π@cveNotify
Stack-based buffer overflow in Windows Storage Spaces Controller allows an authorized attacker to elevate privileges locally.
π@cveNotify
π¨ CVE-2026-58941
In multiple functions of iommu.c, there is a possible out of bounds read/write due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
π@cveNotify
In multiple functions of iommu.c, there is a possible out of bounds read/write due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
π@cveNotify
π¨ CVE-2026-19201
An uncontrolled recursion vulnerability in the Windows SIPA event log parser of Google go-attestation versions up to and including 0.6.1 allows an attacker to cause a denial of service (DoS). The (*WinEvents).readELAMAggregation function recurses for every nested elamAggregation sub-event without enforcing a maximum recursion depth limit, while the size guard is bypassed on recursive execution paths. By submitting a crafted Windows event log containing deeply nested elamAggregation headers, an attacker can exhaust the goroutine call stack, triggering an unrecoverable fatal runtime error (stack overflow) that immediately crashes the verifier application.
π@cveNotify
An uncontrolled recursion vulnerability in the Windows SIPA event log parser of Google go-attestation versions up to and including 0.6.1 allows an attacker to cause a denial of service (DoS). The (*WinEvents).readELAMAggregation function recurses for every nested elamAggregation sub-event without enforcing a maximum recursion depth limit, while the size guard is bypassed on recursive execution paths. By submitting a crafted Windows event log containing deeply nested elamAggregation headers, an attacker can exhaust the goroutine call stack, triggering an unrecoverable fatal runtime error (stack overflow) that immediately crashes the verifier application.
π@cveNotify
GitHub
Fix unbounded recursion vulnerability in Windows ELAM parsing by liamjm Β· Pull Request #506 Β· google/go-attestation
Add recursion depth limit, fix LimitedReader size check, and propagate errors in readELAMAggregation.
Fixes GHSA-hcm6-rjfh-f25p.
A crafted Windows TPM measurement log with deeply nested elamAggrega...
Fixes GHSA-hcm6-rjfh-f25p.
A crafted Windows TPM measurement log with deeply nested elamAggrega...
π¨ CVE-2026-65660
Improper control of generation of code ('code injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
π@cveNotify
Improper control of generation of code ('code injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
π@cveNotify
π¨ CVE-2026-68844
Heap-based buffer overflow in Windows Storage Spaces Controller allows an authorized attacker to execute code locally.
π@cveNotify
Heap-based buffer overflow in Windows Storage Spaces Controller allows an authorized attacker to execute code locally.
π@cveNotify
π¨ CVE-2026-68877
Heap-based buffer overflow in Windows Storage Spaces Controller allows an authorized attacker to execute code locally.
π@cveNotify
Heap-based buffer overflow in Windows Storage Spaces Controller allows an authorized attacker to execute code locally.
π@cveNotify
π¨ CVE-2026-68896
Absolute path traversal in Microsoft Windows Search Component allows an authorized attacker to elevate privileges locally.
π@cveNotify
Absolute path traversal in Microsoft Windows Search Component allows an authorized attacker to elevate privileges locally.
π@cveNotify
π¨ CVE-2026-69424
Heap-based buffer overflow in Windows Distributed File System (DFS) allows an authorized attacker to elevate privileges locally.
π@cveNotify
Heap-based buffer overflow in Windows Distributed File System (DFS) allows an authorized attacker to elevate privileges locally.
π@cveNotify
π¨ CVE-2026-69426
Heap-based buffer overflow in Windows VOLSNAP.SYS allows an authorized attacker to execute code locally.
π@cveNotify
Heap-based buffer overflow in Windows VOLSNAP.SYS allows an authorized attacker to execute code locally.
π@cveNotify
π¨ CVE-2026-69427
Out-of-bounds read in Windows VOLSNAP.SYS allows an authorized attacker to elevate privileges over a network.
π@cveNotify
Out-of-bounds read in Windows VOLSNAP.SYS allows an authorized attacker to elevate privileges over a network.
π@cveNotify
π¨ CVE-2026-69429
Heap-based buffer overflow in Windows IKE Extension allows an authorized attacker to execute code over a network.
π@cveNotify
Heap-based buffer overflow in Windows IKE Extension allows an authorized attacker to execute code over a network.
π@cveNotify
π¨ CVE-2026-69430
Use after free in Windows Embedded Mode Service allows an authorized attacker to elevate privileges locally.
π@cveNotify
Use after free in Windows Embedded Mode Service allows an authorized attacker to elevate privileges locally.
π@cveNotify
π¨ CVE-2026-69540
Use after free in Windows Audio Service allows an authorized attacker to elevate privileges locally.
π@cveNotify
Use after free in Windows Audio Service allows an authorized attacker to elevate privileges locally.
π@cveNotify