[Bug 295225] www/py-postorius: Patch XSS vulnerability

From: <bugzilla-noreply_at_freebsd.org>
Date: Tue, 12 May 2026 11:13:12 UTC
https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=295225

            Bug ID: 295225
           Summary: www/py-postorius: Patch XSS vulnerability
           Product: Ports & Packages
           Version: Latest
          Hardware: Any
               URL: https://gitlab.com/mailman/postorius/-/commit/c4706abd
                    05ba6bcf472fc674b160d3a9d6a4868b
                OS: Any
            Status: New
          Severity: Affects Only Me
          Priority: ---
         Component: Individual Port(s)
          Assignee: sunpoet@FreeBSD.org
          Reporter: einar@isnic.is
          Assignee: sunpoet@FreeBSD.org
             Flags: maintainer-feedback?(sunpoet@FreeBSD.org)

An XSS vulnerability was fixed in postorius in January 2025, but no release has
been made since.

According to https://www.openwall.com/lists/oss-security/2026/05/07/3 this
vulnerability is being exploited.

-- 
You are receiving this mail because:
You are the assignee for the bug.