HIGH8.8
PYSEC-2026-660
Cross Site Request Forgery in mailman
Quick fix
PYSEC-2026-660 — mailman: upgrade to the fixed version with the command below.
pip install --upgrade 'mailman>=2.1.38'Details
In GNU Mailman before 2.1.38, a list member or moderator can get a CSRF token and craft an admin request (using that token) to set a new admin password or make other changes.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2021-44227[ADVISORY]
- https://bugs.launchpad.net/mailman/+bug/1952384[WEB]
- https://gitlab.com/mailman/mailman[PACKAGE]
- https://lists.debian.org/debian-lts-announce/2022/06/msg00011.html[WEB]
- https://pypi.org/project/mailman[PACKAGE]
- https://github.com/advisories/GHSA-xq58-69h2-765m[ADVISORY]