EIP-2026-112412

PRE-CVE

SquirrelMail G/PGP Encryption Plugin 2.0/2.1 - Access Validation / Input Validation

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-112412. PoCs published by Tomas Kuliavas.

AI-analyzed exploit summary This exploit demonstrates an XSS vulnerability in the G/PGP encryption plugin for SquirrelMail by injecting arbitrary JavaScript code into a PGP public key block. The vulnerability arises from insufficient input validation, allowing script execution in the context of the application.

Description

SquirrelMail G/PGP Encryption Plugin 2.0/2.1 - Access Validation / Input Validation

Exploits (1)

exploitdb WORKING POC VERIFIED
by Tomas Kuliavas · textwebappsphp
https://www.exploit-db.com/exploits/30859

This exploit demonstrates an XSS vulnerability in the G/PGP encryption plugin for SquirrelMail by injecting arbitrary JavaScript code into a PGP public key block. The vulnerability arises from insufficient input validation, allowing script execution in the context of the application.

Classification
Working Poc 90%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target: SquirrelMail G/PGP Encryption Plugin 2.0, 2.0.1, 2.1
No auth needed
Prerequisites: Access to send an email with a crafted PGP public key block to a victim using the vulnerable plugin
MITRE ATT&CK
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026