Junglewise Threat Intelligence

CVE-2026-57532: pretix stored XSS in PDF layout editor

CVE-2026-57532 · Severity: info · CVSS 8.8 · Published 2026-06-25

Vendors: Pretix.

Executive brief

pretix is an open-source ticketing and event management platform. A security vulnerability in the PDF layout editor allows a malicious administrative user to embed harmful scripts into ticket or badge designs. When another administrator opens the editor to view or modify these designs, the script executes in their browser, potentially allowing the attacker to steal session data or perform actions on behalf of the victim.

Technical details

A stored Cross-Site Scripting (XSS) vulnerability exists in pretix's PDF ticket and badge layout editor. The vulnerability is caused by improper neutralization of HTML tags (CWE-80) within the layout specification. An attacker with backend privileges can inject malicious JavaScript into a layout; this script is then executed when another backend user opens the PDF editor. Notably, this specific component lacks the strong Content-Security-Policy (CSP) present in the rest of the pretix backend due to technical requirements of the PDF rendering libraries, making the XSS fully exploitable. The issue is fixed in versions 2026.3.4, 2026.4.4, and 2026.5.2.

Affected products

  • pretix pretix < 2026.3.4, 2026.4.0 to < 2026.4.4, 2026.5.0 to < 2026.5.2

Timeline

  • 2026-06-25: disclosed: Discovered internally by the pretix team.
  • 2026-06-25: patched: Released in versions 2026.3.4, 2026.4.4, and 2026.5.2.
  • 2026-06-25: advisory

References