Improper Encoding or Escaping of Output Affecting pretalx package, versions [,2026.1.0)


Severity

Recommended
0.0
medium
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.03% (10th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Improper Encoding or Escaping of Output vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-PYTHON-PRETALX-16432010
  • published6 May 2026
  • disclosed18 Apr 2026
  • creditmarkfijneman

Introduced: 18 Apr 2026

NewCVE-2026-41426  (opens in a new tab)
CWE-116  (opens in a new tab)
CWE-79  (opens in a new tab)

How to fix?

Upgrade pretalx to version 2026.1.0 or higher.

Overview

pretalx is a Conference organisation: CfPs, scheduling, much more

Affected versions of this package are vulnerable to Improper Encoding or Escaping of Output via unescaped user-controlled placeholders in mail templates. An attacker can inject arbitrary HTML content into outgoing emails by embedding malicious HTML or markdown link syntax in fields such as the account display name. This allows the attacker to send emails that appear to originate from a legitimate sender address, potentially enabling phishing attacks against recipients.

CVSS Base Scores

version 4.0
version 3.1