> USN-8323-1: Postorius vulnerability
[DATE: 27/05/2026 13:28]
[LANGUAGE: EN]
It was discovered that Postorius did not properly escape HTML in message
subjects when rendering the Held messages pop-up. An attacker could
possibly use this issue to inject arbitrary HTML, resulting in exposure
of sensitive information.