Bug 2531477 - CVE-2026-88859 evolution: evolution: javascript execution via spoofed vCard control bypasses mail script-markup restriction [fedora-all]
Summary: CVE-2026-88859 evolution: evolution: javascript execution via spoofed vCard c...
Keywords:
Status: CLOSED ERRATA
Alias: None
Product: Fedora
Classification: Fedora
Component: evolution
Version: rawhide
Hardware: Unspecified
OS: Unspecified
medium
medium
Target Milestone: ---
Assignee: Milan Crha
QA Contact: Fedora Extras Quality Assurance
URL:
Whiteboard: {"flaws": ["c9b05bd9-1e63-4c86-bbf3-d...
Depends On:
Blocks: 2531401
TreeView+ depends on / blocked
 
Reported: 2026-09-10 14:25 UTC by Vladimir Vasilev
Modified: 2026-09-24 00:17 UTC (History)
4 users (show)

Fixed In Version: evolution-3.58.3-2.fc43 evolution-3.60.2-2.fc44 evolution-3.62.0-1.fc45
Clone Of:
Environment:
Last Closed: 2026-09-19 00:58:06 UTC
Type: ---
Embargoed:


Attachments (Terms of Use)

Description Vladimir Vasilev 2026-09-10 14:25:12 UTC
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.

Evolution's mail display trusted-JavaScript handler
(Evo.MailDisplayBindDOM(), in the WebKitGTK web-extension layer) binds a
privileged click handler to any DOM element matching the CSS class used for
vCard formatter controls, without verifying that the element actually
originated from Evolution's own vCard rendering.

A malicious HTML email can include a spoofed control carrying a custom
"evo-iframe-uri" attribute set to a "javascript:" URL. Because this
attribute is not one of the URL attributes WebKit's markup filter
recognizes, a "javascript:" value in it survives sanitization even when
script execution in mail content is disabled (enable-javascript-markup=
false). When a victim clicks the spoofed control, the trusted handler
assigns the attacker-controlled value to an iframe's "src", triggering a
dynamic javascript: navigation that WebKit executes without checking the
document's script-markup policy.

This allows an attacker to execute arbitrary JavaScript in the mail-viewing
context via a single click on a crafted email, bypassing the restriction
that is meant to prevent script execution when viewing mail.

Fixed upstream in Evolution 3.62.0.

Upstream report: https://gitlab.gnome.org/GNOME/evolution/-/work_items/3388

Comment 1 Milan Crha 2026-09-10 15:37:25 UTC
Thanks for a bug report. The rawhide and f45 will get the fix with the 3.62.0 release (to happen tomorrow), where it'll be included. The f44 and f43 need a backport.

Comment 2 Fedora Update System 2026-09-10 16:12:50 UTC
FEDORA-2026-99a4ff5552 (evolution-3.60.2-2.fc44) has been submitted as an update to Fedora 44.
https://bodhi.fedoraproject.org/updates/FEDORA-2026-99a4ff5552

Comment 3 Fedora Update System 2026-09-10 16:14:06 UTC
FEDORA-2026-1ea9bbcb29 (evolution-3.58.3-2.fc43) has been submitted as an update to Fedora 43.
https://bodhi.fedoraproject.org/updates/FEDORA-2026-1ea9bbcb29

Comment 4 Fedora Update System 2026-09-11 02:08:16 UTC
FEDORA-2026-1ea9bbcb29 has been pushed to the Fedora 43 testing repository.
Soon you'll be able to install the update with the following command:
`sudo dnf upgrade --enablerepo=updates-testing --refresh --advisory=FEDORA-2026-1ea9bbcb29`
You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-2026-1ea9bbcb29

See also https://fedoraproject.org/wiki/QA:Updates_Testing for more information on how to test updates.

Comment 5 Fedora Update System 2026-09-11 02:28:18 UTC
FEDORA-2026-99a4ff5552 has been pushed to the Fedora 44 testing repository.
Soon you'll be able to install the update with the following command:
`sudo dnf upgrade --enablerepo=updates-testing --refresh --advisory=FEDORA-2026-99a4ff5552`
You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-2026-99a4ff5552

See also https://fedoraproject.org/wiki/QA:Updates_Testing for more information on how to test updates.

Comment 6 Fedora Update System 2026-09-14 08:47:24 UTC
FEDORA-2026-5debc0de2b (evolution-3.62.0-1.fc45, evolution-data-server-3.62.0-1.fc45, and 1 more) has been submitted as an update to Fedora 45.
https://bodhi.fedoraproject.org/updates/FEDORA-2026-5debc0de2b

Comment 7 Fedora Update System 2026-09-15 01:26:43 UTC
FEDORA-2026-5debc0de2b has been pushed to the Fedora 45 testing repository.
Soon you'll be able to install the update with the following command:
`sudo dnf upgrade --enablerepo=updates-testing --refresh --advisory=FEDORA-2026-5debc0de2b`
You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-2026-5debc0de2b

See also https://fedoraproject.org/wiki/QA:Updates_Testing for more information on how to test updates.

Comment 8 Fedora Update System 2026-09-19 00:58:06 UTC
FEDORA-2026-1ea9bbcb29 (evolution-3.58.3-2.fc43) has been pushed to the Fedora 43 stable repository.
If problem still persists, please make note of it in this bug report.

Comment 9 Fedora Update System 2026-09-19 01:14:08 UTC
FEDORA-2026-99a4ff5552 (evolution-3.60.2-2.fc44) has been pushed to the Fedora 44 stable repository.
If problem still persists, please make note of it in this bug report.

Comment 10 Fedora Update System 2026-09-24 00:17:17 UTC
FEDORA-2026-5debc0de2b (evolution-3.62.0-1.fc45, evolution-data-server-3.62.0-1.fc45, and 1 more) has been pushed to the Fedora 45 stable repository.
If problem still persists, please make note of it in this bug report.


Note You need to log in before you can comment on or make changes to this bug.