


Perceptive Security
SOC/SIEM Consultancy

PasswordPusher before 2.8.1 accepts data URI schemes in URL push payloads due to insufficient validation in the valid_url function. Attackers can create malicio…
Published:
7 juli 2026 om 22:00:00
Alert date:
8 juli 2026 om 21:04:14
Source:
nvd.nist.gov
Web Technologies, Identity & Access
CVE-2026-59802 affects PasswordPusher versions before 2.8.1, where insufficient validation in the valid_url function allows attackers to inject data URI schemes (data:text/html) into URL push payloads. When victims click these malicious links, arbitrary JavaScript executes in their browsers under the trusted PasswordPusher domain. This enables phishing attacks and credential theft, as the malicious content appears to originate from a trusted password-sharing service. The vulnerability is classified as a redirect-based XSS via data URI. A fix was introduced in version 2.8.1. The issue is documented in the official GitHub security advisory and by VulnCheck.
Technical details
Mitigation steps:
Affected products:
PasswordPusher
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-59802
https://github.com/pglombardo/PasswordPusher/security/advisories/GHSA-76c2-66pg-fj2f
https://www.vulncheck.com/advisories/passwordpusher-redirect-based-xss-via-data-uri-in-url-push-payload
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
