Description
Cross-site scripting in the webmail of Progressive Robot hMailServer 6.3.2 through 6.3.5 allows a remote attacker who can send a user an encrypted message to run script in the webmail's origin with that user's session. When the webmail decrypted an S/MIME message (from 6.3.2) or an OpenPGP message (from 6.3.4) in the browser, it offered each decrypted attachment as a blob URL of the media type the message declared for it. A click saved the file, but if the user opened the attachment in a new tab, a part declared as text/html was rendered as a document of the webmail's origin and its script could read the mailbox, send mail and change the account through the REST API. The webmail is served only when the REST API is enabled, which it is not by default.
Published: 2026-10-08
Score: 8 High
EPSS: n/a
KEV: No
Impact: Remote Code Execution via XSS
Action: Patch Immediately
AI Analysis

Impact

Cross‑site scripting occurs in hMailServer’s webmail interface for versions 6.3.2 through 6.3.5 when a user opens a decrypted S/MIME or OpenPGP attachment in a new browser tab. The attachment is served as a blob URL with the media type declared in the message. If that type is text/html, the browser renders it as a document belonging to the webmail’s origin, allowing injected script to read the user’s mailbox, send mail, and modify the account through the REST API. This effectively gives a remote attacker the ability to run code within the victim’s session.

Affected Systems

Progressive Robot Ltd hMailServer versions 6.3.2 to 6.3.5 are affected. The webmail feature is exposed only when the REST API is enabled, which is not enabled by default.

Risk and Exploitability

The vulnerability receives a CVSS score of 8, with no EPSS score available and not listed in CISA KEV. An attacker who can send an encrypted message to a user can exploit this by having the user open the attachment in a new tab, which is a user‑triggered attack. Because the webmail interface is normally protected behind the REST API, the practical exposure depends on the API being enabled and a user accessing a crafted encrypted message. The CVSS score indicates a high likelihood of serious impact if exploited, and the lack of EPSS data suggests limited public exploitation evidence to date.

Generated by OpenCVE AI on October 8, 2026 at 12:50 UTC.

Remediation

Vendor Solution

Upgrade to hMailServer 6.3.6, which hands every decrypted attachment to the browser as application/octet-stream so that it is only ever saved. Until then: keep the REST API off (RestApiPort 0, the default), or tell webmail users not to open decrypted attachments in a new tab.


OpenCVE Recommended Actions

  • Upgrade to hMailServer 6.3.6, which delivers all decrypted attachments as application/octet-stream, preventing their rendering as HTML.
  • Configure the server to disable the REST API by setting RestApiPort to 0, so the webmail interface is not served.
  • Instruct webmail users to avoid opening decrypted attachments in a new browser tab.

Generated by OpenCVE AI on October 8, 2026 at 12:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 08 Oct 2026 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 08 Oct 2026 13:00:00 +0000

Type Values Removed Values Added
First Time appeared Progressive Robot
Progressive Robot hmailserver
Vendors & Products Progressive Robot
Progressive Robot hmailserver

Thu, 08 Oct 2026 11:00:00 +0000

Type Values Removed Values Added
Description Cross-site scripting in the webmail of Progressive Robot hMailServer 6.3.2 through 6.3.5 allows a remote attacker who can send a user an encrypted message to run script in the webmail's origin with that user's session. When the webmail decrypted an S/MIME message (from 6.3.2) or an OpenPGP message (from 6.3.4) in the browser, it offered each decrypted attachment as a blob URL of the media type the message declared for it. A click saved the file, but if the user opened the attachment in a new tab, a part declared as text/html was rendered as a document of the webmail's origin and its script could read the mailbox, send mail and change the account through the REST API. The webmail is served only when the REST API is enabled, which it is not by default.
Title Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in hMailServer
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 8, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:N'}


Subscriptions

Progressive Robot Hmailserver
cve-icon MITRE

Status: PUBLISHED

Assigner: GitLab

Published:

Updated: 2026-10-08T14:22:56.590Z

Reserved: 2026-10-01T07:04:34.908Z

Link: CVE-2026-103647

cve-icon Vulnrichment

Updated: 2026-10-08T14:22:52.810Z

cve-icon NVD

Status : Received

Published: 2026-10-08T11:16:42.950

Modified: 2026-10-08T15:17:31.617

Link: CVE-2026-103647

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T13:00:07Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')