Executive brief
A security vulnerability exists in bluebox, a specialized email server and webmail client used for application testing. An attacker could potentially execute malicious scripts in a user's browser by tricking them into interacting with a specially crafted link. This could lead to unauthorized actions being performed on behalf of the user within the webmail interface.
Technical details
A cross-site scripting (XSS) vulnerability exists in stephen-kruger bluebox through version 4.5.12. The flaw is caused by improper neutralization of input during web page generation (CWE-79) specifically involving the 'code' argument. A remote, unauthenticated attacker can exploit this by persuading a user to visit a malicious URL, leading to the execution of arbitrary JavaScript in the context of the user's session. While the specific affected component is not fully detailed, the vulnerability is classified as both XSS and potentially code injection (CWE-94). A public exploit has been reported.
Affected products
- stephen-kruger bluebox up to 4.5.12
Timeline
- 2026-06-02: disclosed: Issue reported to the developer via GitHub
- 2026-07-05: advisory: CVE published by VulDB/NVD