top of page
perceptive_background_267k.jpg

PasswordPusher before 2.8.1 accepts data URI schemes in URL push payloads due to insufficient validation in the valid_url function. Attackers can create malicio…

Published:

7 juli 2026 om 22:00:00

Alert date:

8 juli 2026 om 21:04:14

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies, Identity & Access

CVE-2026-59802 affects PasswordPusher versions before 2.8.1, where insufficient validation in the valid_url function allows attackers to inject data URI schemes (data:text/html) into URL push payloads. When victims click these malicious links, arbitrary JavaScript executes in their browsers under the trusted PasswordPusher domain. This enables phishing attacks and credential theft, as the malicious content appears to originate from a trusted password-sharing service. The vulnerability is classified as a redirect-based XSS via data URI. A fix was introduced in version 2.8.1. The issue is documented in the official GitHub security advisory and by VulnCheck.

Technical details

Mitigation steps:

Affected products:

PasswordPusher

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page