Executive brief
Evolution is a widely-used email and calendar application. This vulnerability allows a remote attacker to execute malicious JavaScript code within the context of an email message by sending a specially crafted HTML email with a spoofed vCard control. When a user clicks on the malicious control, arbitrary JavaScript runs with access to sensitive email data and could lead to credential theft or further system compromise.
Technical details
This vulnerability is a CWE-84 improper neutralization of encoded URI schemes that bypasses Evolution's HTML email script-execution restrictions. The root cause lies in Evolution's trusted JavaScript handler incorrectly assigning an attacker-controlled JavaScript URL to an iframe's source attribute when processing a spoofed vCard control embedded in HTML email content. The attack requires network connectivity and user interaction (clicking the malicious control), but no authentication or special privileges. A successful exploit results in arbitrary JavaScript execution within the mail-viewing context, potentially exposing email content and user credentials. Mitigation is available by disabling JavaScript execution via gsettings, though this may impact legitimate HTML email rendering.
Affected products
- GNOME Evolution
Timeline
- 2026-09-10: disclosed