Executive brief
Bulwark Webmail is a self-hosted email client. A security flaw in its built-in proxy allowed malicious scripts in emails to run in a user's browser because security protections were set to 'report-only' mode instead of being enforced. This could allow an attacker to steal login sessions or perform unauthorized actions on behalf of a user who opens a malicious email.
Technical details
A vulnerability exists in Bulwark Webmail's reverse proxy (proxy.ts) where the Content-Security-Policy-Report-Only header was used instead of the enforcing Content-Security-Policy header. This misconfiguration effectively disabled CSP protections, allowing Cross-Site Scripting (XSS) attacks to proceed unblocked. An attacker can exploit this by sending a crafted HTML email containing malicious scripts. If a user views the email, the script executes in the context of the webmail application, enabling session token theft or unauthorized state-changing actions. The issue is resolved in version 1.4.11 by switching to an enforcing CSP header.
Affected products
- Bulwark Webmail < 1.4.11
Timeline
- 2026-04-02: advisory: GitHub Security Advisory published
- 2026-04-06: disclosed: CVE published to NVD
- 2026-04-06: patched: Fix released in version 1.4.11