Description
FairEmail is a fully featured, open source, privacy-friendly email app for Android. Prior to 1.2319, the ActivityAMP AMP message renderer in app/src/main/java/eu/faircode/email/ActivityAMP.java enables JavaScript in its WebView but incompletely sanitizes untrusted message HTML. For non-allowlisted hosts, script.removeAttr("src") leaves inline script elements in the document and does not reject event-handler attributes or javascript: URLs on other elements. A crafted AMP email can execute arbitrary JavaScript when a recipient opens the message and enables the AMP toggle. The script can read the message DOM, exfiltrate message data, and display phishing overlays within the message-body area. Exploitation requires the recipient to enable the AMP toggle, and practical exposure is reduced because AMP email is uncommon. This issue is fixed in version 1.2319.
Published: 2026-09-17
Score: 6.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Client‑side XSS
Action: Patch or Disable AMP
AI Analysis

Impact

FairEmail’s AMP renderer called ActivityAMP processes AMP email content in a WebView. The renderer enables JavaScript execution but does not fully sanitize untrusted HTML. A crafted AMP message can inject inline scripts, event‑handler attributes or javascript: URLs that survive the incomplete cleaning. When the recipient turns on the AMP toggle and views the message, the malicious code runs inside the app’s WebView, allowing the attacker to read the DOM, exfiltrate information, and show phishing overlays.

Affected Systems

All installations of FairEmail by M66B released before version 1.2319 are affected, regardless of operating system version. The vendor is M66B and the product is FairEmail; users of any earlier Android build should verify their version.

Risk and Exploitability

The CVSS score of 6.1 indicates moderate severity. The EPSS value is less than 1%, suggesting low likelihood of widespread exploitation in the near term. The vulnerability is not on the CISA KEV list, meaning no publicly known exploits have been confirmed. Attack requires user interaction: the message must be opened and the AMP toggle enabled. Because AMP emails are uncommon, practical exposure is limited, but an attacker who succeeds can gain client‑side control within the app.

Generated by OpenCVE AI on September 19, 2026 at 02:19 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Install FairEmail 1.2319 or newer, which removes the insecure ActivityAMP renderer.
  • If an upgrade cannot be performed immediately, disable the AMP toggle in the app’s settings to prevent AMP content from being rendered.
  • Educate users to refrain from enabling AMP for unknown senders and consider filtering or blocking suspicious AMP emails at the server or client level.

Generated by OpenCVE AI on September 19, 2026 at 02:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared M66b
M66b fairemail
Vendors & Products M66b
M66b fairemail
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Description FairEmail is a fully featured, open source, privacy-friendly email app for Android. Prior to 1.2319, the ActivityAMP AMP message renderer in app/src/main/java/eu/faircode/email/ActivityAMP.java enables JavaScript in its WebView but incompletely sanitizes untrusted message HTML. For non-allowlisted hosts, script.removeAttr("src") leaves inline script elements in the document and does not reject event-handler attributes or javascript: URLs on other elements. A crafted AMP email can execute arbitrary JavaScript when a recipient opens the message and enables the AMP toggle. The script can read the message DOM, exfiltrate message data, and display phishing overlays within the message-body area. Exploitation requires the recipient to enable the AMP toggle, and practical exposure is reduced because AMP email is uncommon. This issue is fixed in version 1.2319.
Title FairEmail: Cross-site scripting (XSS) in AMP message rendering (ActivityAMP)
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-18T20:08:14.389Z

Reserved: 2026-06-15T18:40:01.651Z

Link: CVE-2026-54521

cve-icon Vulnrichment

Updated: 2026-09-18T20:08:10.223Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-17T21:17:16.397

Modified: 2026-09-23T18:12:04.247

Link: CVE-2026-54521

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T02:30:17Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')