CVE-2025-52557

HIGH

Mail-0's Zero <0.8 - XSS

Title source: llm
STIX 2.1

Description

Mail-0's Zero is an open-source email solution. In version 0.8 it's possible for an attacker to craft an email that executes javascript leading to session hijacking due to improper sanitization. This issue has been patched in version 0.81.

Scores

CVSS v4 8.6
EPSS 0.0036
EPSS Percentile 58.4%
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-1384
Status published
Products (1)
Mail-0/Zero = 0.8
Published Jun 21, 2025
Tracked Since Feb 18, 2026