logo

Zero-Click pretalx XSS Flaw Lets Hackers Hijack Conference Organizer Accounts

ID: d392613f-6419-501d-b23a-877c182f6d07

STIX ID: report--d392613f-6419-501d-b23a-877c182f6d07

Feed Name: HackRead

Threat Score
72/100

Date Published: 2026-06-01

Date Updated: 2026-06-03

Author: Deeba Ahmed

...
...

Novee Security disclosed a high-severity stored XSS in pretalx (CVE-2026-41241, CVSS 8.7) that lets registered users bypass Content Security Policy by using uploaded .js files combined with iframe srcdoc to execute code in organizer contexts and hijack sessions, and also enables admin-demotion via image-based requests; the flaw could be mass-weaponized by automated agents but was patched in pretalx v2026.1.0 on May 27, 2026.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.