GitHub Security Advisory (GHSA-76c2-66pg-fj2f)Vendor advisory
https://github.com/pglombardo/PasswordPusher/security/advisories/GHSA-76c2-66pg-fj2f CVE-2026-59802
MEDIUM
PasswordPusher < 2.8.1 - Redirect-Based XSS via data URI in URL Push Payload
Record summary
CVE-2026-59802 has a selected CVSS score of 6.3 (medium).
Description
PasswordPusher before 2.8.1 accepts data URI schemes in URL push payloads due to insufficient validation in the valid_url function. Attackers can create malicious pushes containing data:text/html URIs that execute arbitrary JavaScript in victims' browsers when clicked, enabling phishing and credential theft under the trusted PasswordPusher domain.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationPoC
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Jul 9, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
PasswordPusherBrowse PasswordPusher / PasswordPusherDefault status: unaffected | CVE List | Before 2.8.1 | affected |
| 2.8.1 | unaffected |
References
2vulncheck.comThird-party advisory
https://www.vulncheck.com/advisories/passwordpusher-redirect-based-xss-via-data-uri-in-url-push-payload