Junglewise Threat Intelligence

CVE-2026-59802: PasswordPusher XSS via data URI in URL push payloads

CVE-2026-59802 · Severity: high · CVSS 8.2 · Published 2026-07-08

Technologies: PasswordPusher.

Executive brief

PasswordPusher, a tool used to securely share sensitive information like passwords and URLs, contains a vulnerability that allows attackers to create malicious links. By tricking a user into clicking a specially crafted PasswordPusher link, an attacker can execute malicious code in the victim's browser. This could lead to the theft of login credentials or sensitive data while appearing to come from a trusted source.

Technical details

A redirect-based Cross-Site Scripting (XSS) vulnerability exists in PasswordPusher's URL push feature. The 'valid_url' function in 'app/models/push.rb' insufficiently validates URI schemes, accepting any non-nil scheme including 'data:'. When a victim views a push of kind 'url', the application performs a 303 redirect to the payload using 'allow_other_host: true'. An unauthenticated attacker can create a push containing a 'data:text/html' URI with a malicious script. When a victim clicks the link, the browser executes the JavaScript in the context of the trusted domain. This has been patched in version 2.8.1 by implementing an allowlist for 'http' and 'https' schemes.

Affected products

  • PasswordPusher PasswordPusher < 2.8.1

Timeline

  • 2026-06-30: advisory: Initial GitHub Security Advisory published
  • 2026-07-08: disclosed: CVE-2026-59802 published to NVD
  • 2026-07-08: patched: Fix confirmed in version 2.8.1

References