VDB
Sign up
HIGH7.2

PYSEC-2026-2891

Postorius is vulnerable to XSS

Details

Postorius through 1.3.13 does not escape HTML in the message subject when rendering it in the Held messages pop-up, as exploited in the wild in May 2026.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/postorius
Introduced in: 0

No fixed version published yet for postorius (pip). Pin to a known-safe version or switch to an alternative.

References