CVE-2026-33284 Details
Description
GlobaLeaks is free and open-source whistleblowing software. Prior to version 5.0.89, the /api/support endpoint of GlobaLeaks performs minimal validation on user-submitted support requests. As a result, arbitrary URLs can be included in support emails sent to administrators. Version 5.0.89 patches the issue.
A vulnerability exists in GlobaLeaks versions prior to 5.0.89, where the /api/support endpoint lacks adequate validation of user-submitted support requests. This flaw enables the inclusion of arbitrary URLs in support emails sent to administrators. Although the vulnerability does not directly impact the GlobaLeaks platform's functionality or security, it poses a low-risk social engineering threat, as administrators may inadvertently click on these links if they are automatically converted to clickable format by certain email clients, such as Gmail or Outlook.
Users can update to GlobaLeaks version 5.0.89 or later, where this vulnerability has been patched. Additionally, administrators can configure their email clients to disable automatic linking of URLs, treat links from untrusted sources with caution, and train staff to be aware of potential phishing risks.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Mar 27, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/globaleaks/globaleaks-whistleblowing-software/security/advisories/GHSA-84wr-q36q-wqhv | [email protected] | ExploitMitigationVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| NVD-CWE-noinfo | Insufficient Information to Classify Weakness | [email protected] |
| CWE-20 | Improper Input Validation | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| globaleaks globaleaks | < 5.0.89 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 10, 2026 | Initial Analysis | [email protected] |
| Mar 27, 2026 | New CVE Received | [email protected] |