CVE-2026-59802 MEDIUM

CVE-2026-59802: PasswordPusher < 2.8.1 - Redirect-Based XSS via data URI in URL Push Payload

Vendor Passwordpusher
Product PasswordPusher
Weakness CWE-183
Published July 8, 2026
Last update July 9, 2026

CVSS base score

6.3/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:H/SI:L/SA:N

What the vulnerability does

01Description

PasswordPusher before 2.8.1 accepts data URI schemes in URL push payloads due to insufficient validation in the valid_url function. Attackers can create malicious pushes containing data:text/html URIs that execute arbitrary JavaScript in victims' browsers when clicked, enabling phishing and credential theft under the trusted PasswordPusher domain.

Key dates

02Disclosure timeline

July 8, 2026 CVE published
July 9, 2026 Record updated