CVE-2026-88859

Public on 2026-09-10
Modified on 2026-09-11
Description
A flaw was found in Evolution. A remote attacker can exploit this vulnerability by sending a specially crafted HTML email containing a spoofed vCard control. When a victim clicks on this control, Evolution's trusted JavaScript handler incorrectly assigns an attacker-controlled JavaScript URL to an iframe's source. This action leads to arbitrary JavaScript execution within the mail-viewing context, effectively bypassing the security measures designed to prevent script execution in email content.
Severity
Medium severity
Medium
See what this means
CVSS v3 Base Score
5.3
See breakdown

Affected Packages

Platform Package Release Date Advisory Status
Amazon Linux 2 - Core evolution Not Affected
Amazon Linux 2 - Core evolution-data-server Not Affected
Amazon Linux 2023 evolution-data-server Not Affected
Amazon Linux 2027 Preview evolution-data-server Not Affected
Amazon Linux 2 - Core evolution-ews Not Affected
Amazon Linux 2 - Core evolution-mapi Not Affected

CVSS Scores

Score Type Score Vector
Amazon Linux CVSSv3 5.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L