Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-88859— Evolution: evolution: javascript execution via spoofed vcard control bypasses mail script-markup restriction

Quick assessment

Affected
Red Hat Red Hat Enterprise Linux 6
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Evolution 中发现了一个缺陷。远程攻击者可以通过发送一封经过精心构造的 HTML 电子邮件来利用此漏洞,该邮件中包含一个伪造的 vCard 控件。当受害者点击该控件时,Evolution 中受信任的 JavaScript 处理程序错误地将攻击者控制的 JavaScript URL 赋给 iframe 的 source 属性。这一操作导致在查看邮件的上下文中执行任意 JavaScript,从而有效规避了旨在防止电子邮件内容中脚本执行的安全机制。

CVSS 6.3 · Medium

Possible ATT&CK Techniques 2 AI

T1189 · Drive-by Compromise T1189.002
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-88859

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Evolution: evolution: javascript execution via spoofed vcard control bypasses mail script-markup restriction
Source: CVE Program / CVE List V5
Vulnerability Description
A flaw was found in Evolution. A remote attacker can exploit this vulnerability by sending a specially crafted HTML email containing a spoofed vCard control. When a victim clicks on this control, Evolution's trusted JavaScript handler incorrectly assigns an attacker-controlled JavaScript URL to an iframe's source. This action leads to arbitrary JavaScript execution within the mail-viewing context, effectively bypassing the security measures designed to prevent script execution in email content.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L
Source: CVE Program / CVE List V5
Vulnerability Type
Web页面编码URIScheme转义处理不恰当
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Red Hat Red Hat Enterprise Linux 6 - cpe:/o:redhat:enterprise_linux:6
Red Hat Red Hat Enterprise Linux 7 - cpe:/o:redhat:enterprise_linux:7
Red Hat Red Hat Enterprise Linux 8 - cpe:/o:redhat:enterprise_linux:8
Red Hat Red Hat Enterprise Linux 9 - cpe:/o:redhat:enterprise_linux:9

II. Public POCs for CVE-2026-88859

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-88859

登录查看更多情报信息。

Vendor Pages for CVE-2026-88859 (1)

Other References for CVE-2026-88859 (1)

Same Patch Batch · Red Hat · 2026-09-10 · 8 CVEs total

CVE-2026-84042 7.8 HIGH Crun: crun: rootful krun with passt executes container payload as host root
CVE-2026-88924 7.0 HIGH Gvfs: gvfs-admin socket ownership race permits local root
CVE-2026-84828 6.5 MEDIUM Pcs: pcs: non-root haclient users can read arbitrary files via pcs host auth --token
CVE-2026-88770 6.5 MEDIUM Keycloak-services: keycloak-services: device authorization grant issues tokens to brute-fo
CVE-2026-88763 5.9 MEDIUM Skupper-router: skupper-router: unbounded recursion in amqp field parser leads to denial o
CVE-2026-88265 5.6 MEDIUM Crun: crun: /dev/null symlink follow during stdio reopen allows host bind-mount write and
CVE-2026-88264 5.6 MEDIUM Crun: crun: /dev/console symlink follow allows root-owned file creation outside the rootfs

IV. Related Vulnerabilities

V. Comments for CVE-2026-88859

No comments yet


Leave a comment