Mail-0's Zero is an open-source email solution. In version 0.8 it's possible for an attacker to craft an email that executes javascript leading to session hijacking due to improper sanitization. This issue has been patched in version 0.81.
https://github.com/Mail-0/Zero/security/advisories/GHSA-34gh-g567-hq85
https://github.com/Mail-0/Zero/pull/1386
https://github.com/Mail-0/Zero/commit/48d1df65b62c9c57897b72b241081f447140342f
Published: 2025-06-21
Updated: 2025-06-21
Base Score: 4.3
Vector: CVSS2#AV:N/AC:M/Au:N/C:N/I:P/A:N
Severity: Medium
Base Score: 5.4
Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
Severity: Medium
Base Score: 8.6
Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Severity: High
EPSS: 0.0004