HIGH7.2
PYSEC-2026-2891
Postorius is vulnerable to XSS
Details
Postorius through 1.3.13 does not escape HTML in the message subject when rendering it in the Held messages pop-up, as exploited in the wild in May 2026.
Are you affected?
Enter the version of the package you're using.
Affected packages
PyPI/postorius
Introduced in:
0No fixed version published yet for postorius (pip). Pin to a known-safe version or switch to an alternative.
References
- https://nvd.nist.gov/vuln/detail/CVE-2026-44742[ADVISORY]
- https://gitlab.com/mailman/postorius[PACKAGE]
- https://gitlab.com/mailman/postorius/-/commit/c4706abd05ba6bcf472fc674b160d3a9d6a4868b[WEB]
- https://gitlab.com/mailman/postorius/-/issues/620[WEB]
- https://gitlab.com/mailman/postorius/-/merge_requests/972[WEB]
- https://www.openwall.com/lists/oss-security/2026/05/07/3[WEB]
- https://pypi.org/project/postorius[PACKAGE]
- https://github.com/advisories/GHSA-r7c9-7pjq-hmm8[ADVISORY]