Executive brief
EspoCRM, an open-source customer relationship management platform, is vulnerable to a security flaw that allows standard users to inject malicious HTML into system-generated emails. By posting a specially crafted note or mention, an attacker can cause the system to send emails containing deceptive content, such as fake login forms or tracking pixels, to other users. Because these emails originate from the official system address, they appear legitimate, significantly increasing the risk of successful phishing attacks and unauthorized user tracking within the organization.
Technical details
A stored HTML injection vulnerability exists in EspoCRM's notification system due to improper output encoding in server-side Handlebars templates. Specifically, the 'post' field in stream activity notes is rendered using unescaped triple-brace syntax ({{{post}}}). Furthermore, the Markdown processor (Michelf\Markdown) preserves inline HTML by default, and the rendering pipeline explicitly bypasses sanitization for fields within the 'additionalData' array. An authenticated attacker with standard privileges can exploit this by submitting a note via the API containing malicious HTML. When the system generates email notifications for mentions or posts, the raw HTML is included in the email body. This enables phishing, UI manipulation, and user tracking via image beacons, all delivered via the trusted system SMTP identity. The issue is resolved in version 9.3.4.
Affected products
- EspoCRM EspoCRM <= 9.3.3
Timeline
- 2026-03-24: patched: Version 9.3.4 released
- 2026-04-13: disclosed: Security advisory published
- 2026-04-13: advisory: CVE-2026-33657 assigned