CVE-2026-59802 Details
Description
PasswordPusher before 2.8.1 accepts data URI schemes in URL push payloads due to insufficient validation in the valid_url function. Attackers can create malicious pushes containing data:text/html URIs that execute arbitrary JavaScript in victims' browsers when clicked, enabling phishing and credential theft under the trusted PasswordPusher domain.
A cross-site scripting vulnerability has been identified in PasswordPusher versions prior to 2.8.1. The issue arises from inadequate validation of URL push payloads, allowing attackers to inject data URIs that execute arbitrary JavaScript in the browsers of users who click the links. This exploitation occurs under the trusted PasswordPusher domain, facilitating phishing and credential theft.
Users are advised to update PasswordPusher to version 2.8.1 or later, where this vulnerability has been patched.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jul 8, 2026CISA-ADP
Assessed Jul 9, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/pglombardo/PasswordPusher/security/advisories/GHSA-76c2-66pg-fj2f | CISA-ADP | AdvisoryExploitRemedyVendor |
| https://github.com/pglombardo/PasswordPusher/security/advisories/GHSA-76c2-66pg-fj2f | [email protected] | AdvisoryExploitRemedyVendor |
| https://www.vulncheck.com/advisories/passwordpusher-redirect-based-xss-via-data-uri-in-url-push-payload | [email protected] | Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-183 | Permissive List of Allowed Inputs | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| PasswordPusher | <= 2.8.0 (semver) |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 14, 2026 | CVE Modified | [email protected] |
| Jul 9, 2026 | CVE Modified | CISA-ADP |
| Jul 8, 2026 | New CVE Received | [email protected] |
Volerion