CVE-2026-26266 | AliasVault up to 0.25.x Email cross site scripting (GHSA-f65p-p65r-g53q)
A vulnerability was found in AliasVault up to 0.25.x. It has been classified as problematic. Impacted is an unknown function of the component Email Handler. This manipulation causes cross site scripting.
This vulnerability is handled as CVE-2026-26266. The attack can be initiated remotely. There is not any exploit available.
Upgrading the affected component is recommended.