VDB
Sign up
HIGH8.8

PYSEC-2026-660

Cross Site Request Forgery in mailman

Quick fix

PYSEC-2026-660 — mailman: upgrade to the fixed version with the command below.

pip install --upgrade 'mailman>=2.1.38'

Details

In GNU Mailman before 2.1.38, a list member or moderator can get a CSRF token and craft an admin request (using that token) to set a new admin password or make other changes.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/mailman
Introduced in: 0Fixed in: 2.1.38
Fixpip install --upgrade 'mailman>=2.1.38'

References