Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Workaround
To mitigate this issue, users can disable JavaScript execution for HTML mail in Evolution. This can be done through the Evolution preferences or by using `gsettings`. Disabling JavaScript may affect the rendering and functionality of some legitimate HTML emails. To disable JavaScript via `gsettings`, execute the following command: `gsettings set org.gnome.evolution.mail enable-javascript false` To revert this change, execute: `gsettings set org.gnome.evolution.mail enable-javascript true` Note that changes to `gsettings` take effect immediately, but Evolution may need to be restarted for the setting to be fully applied to already open mail views.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 10 Sep 2026 12:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 10 Sep 2026 11:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw was found in Evolution. A remote attacker can exploit this vulnerability by sending a specially crafted HTML email containing a spoofed vCard control. When a victim clicks on this control, Evolution's trusted JavaScript handler incorrectly assigns an attacker-controlled JavaScript URL to an iframe's source. This action leads to arbitrary JavaScript execution within the mail-viewing context, effectively bypassing the security measures designed to prevent script execution in email content. | |
| Title | Evolution: evolution: javascript execution via spoofed vcard control bypasses mail script-markup restriction | |
| First Time appeared |
Redhat
Redhat enterprise Linux |
|
| Weaknesses | CWE-84 | |
| CPEs | cpe:/o:redhat:enterprise_linux:6 cpe:/o:redhat:enterprise_linux:7 cpe:/o:redhat:enterprise_linux:8 cpe:/o:redhat:enterprise_linux:9 |
|
| Vendors & Products |
Redhat
Redhat enterprise Linux |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2026-09-10T11:37:19.259Z
Reserved: 2026-09-10T10:42:51.932Z
Link: CVE-2026-88859
Updated: 2026-09-10T11:37:12.696Z
Status : Awaiting Analysis
Published: 2026-09-10T12:16:33.980
Modified: 2026-09-10T14:50:07.813
Link: CVE-2026-88859
No data.
OpenCVE Enrichment
Updated: 2026-09-10T12:30:07Z