CVE-2026-54521: CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in M66B FairEmail
CVE-2026-54521 is a cross-site scripting (XSS) vulnerability in the FairEmail Android app prior to version 1.2319. The flaw exists in the ActivityAMP AMP message renderer, which enables JavaScript in its WebView but does not fully sanitize untrusted AMP email HTML content. This allows crafted AMP emails to execute arbitrary JavaScript when the recipient enables the AMP toggle. Exploitation can lead to reading message content, data exfiltration, and phishing overlays within the message body. The vulnerability requires user interaction to enable the AMP toggle and is mitigated by the rarity of AMP emails. The issue is fixed in FairEmail version 1.2319.
AI Analysis
Technical Summary
FairEmail versions prior to 1.2319 contain a CWE-79 cross-site scripting vulnerability in the ActivityAMP AMP message renderer. The renderer enables JavaScript in its WebView but incompletely sanitizes untrusted AMP email HTML. Specifically, for non-allowlisted hosts, the sanitization removes the 'src' attribute from script elements but leaves inline scripts intact and does not reject event-handler attributes or 'javascript:' URLs on other elements. This allows an attacker to craft an AMP email that executes arbitrary JavaScript when the recipient opens the message and enables the AMP toggle. The malicious script can access the message DOM, exfiltrate data, and display phishing overlays. The vulnerability is fixed in version 1.2319.
Potential Impact
Successful exploitation allows arbitrary JavaScript execution within the AMP message renderer WebView, enabling attackers to read email message content, exfiltrate sensitive data, and display phishing overlays. This compromises confidentiality and integrity of email content. However, exploitation requires the recipient to enable the AMP toggle, and AMP emails are uncommon, reducing practical exposure.
Mitigation Recommendations
Upgrade FairEmail to version 1.2319 or later, where this vulnerability is fixed. Users should avoid enabling the AMP toggle on untrusted emails until patched. No other vendor advisories indicate additional mitigations or that no action is required.
CVE-2026-54521: CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in M66B FairEmail
Description
CVE-2026-54521 is a cross-site scripting (XSS) vulnerability in the FairEmail Android app prior to version 1.2319. The flaw exists in the ActivityAMP AMP message renderer, which enables JavaScript in its WebView but does not fully sanitize untrusted AMP email HTML content. This allows crafted AMP emails to execute arbitrary JavaScript when the recipient enables the AMP toggle. Exploitation can lead to reading message content, data exfiltration, and phishing overlays within the message body. The vulnerability requires user interaction to enable the AMP toggle and is mitigated by the rarity of AMP emails. The issue is fixed in FairEmail version 1.2319.
CVSS v3.1
Score 6.1medium
Affected software
M66B
FairEmail
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
FairEmail versions prior to 1.2319 contain a CWE-79 cross-site scripting vulnerability in the ActivityAMP AMP message renderer. The renderer enables JavaScript in its WebView but incompletely sanitizes untrusted AMP email HTML. Specifically, for non-allowlisted hosts, the sanitization removes the 'src' attribute from script elements but leaves inline scripts intact and does not reject event-handler attributes or 'javascript:' URLs on other elements. This allows an attacker to craft an AMP email that executes arbitrary JavaScript when the recipient opens the message and enables the AMP toggle. The malicious script can access the message DOM, exfiltrate data, and display phishing overlays. The vulnerability is fixed in version 1.2319.
Potential Impact
Successful exploitation allows arbitrary JavaScript execution within the AMP message renderer WebView, enabling attackers to read email message content, exfiltrate sensitive data, and display phishing overlays. This compromises confidentiality and integrity of email content. However, exploitation requires the recipient to enable the AMP toggle, and AMP emails are uncommon, reducing practical exposure.
Mitigation Recommendations
Upgrade FairEmail to version 1.2319 or later, where this vulnerability is fixed. Users should avoid enabling the AMP toggle on untrusted emails until patched. No other vendor advisories indicate additional mitigations or that no action is required.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-06-15T18:40:01.651Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6aac51eb55bf5e2cf5e0e5be
Added to database: 09/17/2026, 20:47:39 UTC
Last enriched: 09/17/2026, 21:02:09 UTC
Last updated: 09/17/2026, 21:02:09 UTC
Views: 5
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.