{"document":{"acknowledgments":[{"urls":["https://kb.cert.org/vuls/id/487613#acknowledgements"]}],"category":"CERT/CC Vulnerability Note","csaf_version":"2.0","notes":[{"category":"summary","text":"### Overview\r\nA cross-site scripting (XSS) vulnerability in Alinto SOGo v5.12.7 allows attackers to achieve remote code execution by embedding malicious SVG (Scalable Vector Graphics) objects in ICS (iCalendar) invitations. The vulnerability has been actively exploited in the wild, as confirmed by VirusTotal sightings.\r\n\r\n### Description\r\nAlinto SOGo is an open-source webmail and groupware platform for email, calendars, contacts, and shared scheduling. It is primarily used by organizations seeking a self-hosted interface solution for existing mail infrastructure.\r\n\r\n**CVE-2026-8496**\r\nThe vulnerability exists in SOGo’s handling of ICS files, where the `DESCRIPTION` field is rendered without proper sanitization or Content Security Policy (CSP) enforcement. When a calendar invite contains an SVG payload, such as `<animate onrepeat='...'>`, with JavaScript event handlers, the browser executes the script in the context of the SOGo webmail interface. This occurs during normal calendar view rendering (e.g., when a user opens or previews the calendar tab), even without explicit interaction.\r\n\r\n### Impact\r\nOnce an attacker delivers a malicious ICS file via email, any user who views the calendar will execute the embedded XSS payload, granting the attacker full read access to the victim's mailbox. This enables:  \r\n* Credential theft through forced logout/login phishing  \r\n* Password manager autofill hijacking  \r\n* Full exfiltration of email messages, folder contents, and metadata  \r\n* Extraction of contact lists and calendar data\r\n\r\n### Solution\r\nUsers are recommended to upgrade to SOGo v5.12.8 or newer. v5.12.8 addresses this issue via sanitizing ICS `DESCRIPTION` content and stricter handling of embedded SVG and HTML. \r\n\r\n### Acknowledgements\r\nThank you to Greg Lesnewich for reporting this issue. This AI-assisted vulnerability note was prepared by Alexander Curtis.","title":"Summary"},{"category":"legal_disclaimer","text":"THIS DOCUMENT IS PROVIDED ON AN 'AS IS' BASIS AND DOES NOT IMPLY ANY KIND OF GUARANTEE OR WARRANTY, INCLUDING THE WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR USE. YOUR USE OF THE INFORMATION ON THE DOCUMENT OR MATERIALS LINKED FROM THE DOCUMENT IS AT YOUR OWN RISK. ","title":"Legal Disclaimer"},{"category":"other","text":"CERT/CC Vulnerability Note is a limited advisory. It primarily identifies vendors impacted by the advisory and not specific products. We only support \"known_affected\" and \"known_not_affected\" status. Please consult the vendor's statements and advisory URL if provided by the vendor for more details ","title":"Limitations of Advisory"}],"publisher":{"category":"coordinator","contact_details":"Email: cert@cert.org, Phone: +1412 268 5800","issuing_authority":"CERT/CC under DHS/CISA https://www.cisa.gov/cybersecurity also see https://kb.cert.org/ ","name":"CERT/CC","namespace":"https://kb.cert.org/"},"references":[{"url":"https://certcc.github.io/certcc_disclosure_policy","summary":"CERT/CC vulnerability disclosure policy"},{"summary":"CERT/CC document released","category":"self","url":"https://kb.cert.org/vuls/id/487613"},{"url":"https://github.com/Alinto/sogo/commit/67ce01ec2a1a7854d8e9f615dd65afb949043e86","summary":"https://github.com/Alinto/sogo/commit/67ce01ec2a1a7854d8e9f615dd65afb949043e86"},{"url":"https://github.com/Alinto/sogo/releases/tag/SOGo-5.12.8","summary":"https://github.com/Alinto/sogo/releases/tag/SOGo-5.12.8"},{"url":"https://www.sogo.nu/news/2026/sogo-v5128-released.html","summary":"https://www.sogo.nu/news/2026/sogo-v5128-released.html"}],"title":"Alinto SOGo v5.12.7 vulnerable to cross-site scripting via malformed ICS calendar invitations","tracking":{"current_release_date":"2026-08-06T18:36:37+00:00","generator":{"engine":{"name":"VINCE","version":"3.0.43"}},"id":"VU#487613","initial_release_date":"2026-08-06 18:36:37.590641+00:00","revision_history":[{"date":"2026-08-06T18:36:37+00:00","number":"1.20260806183637.1","summary":"Released on 2026-08-06T18:36:37+00:00"}],"status":"final","version":"1.20260806183637.1"}},"vulnerabilities":[{"title":"A cross-site scripting (XSS) vulnerability exists in Alinto SOGo, version  5.","notes":[{"category":"summary","text":"A cross-site scripting (XSS) vulnerability exists in Alinto SOGo, version  5.12.7. A maliciously crafted ICS calendar invitation files allows arbitrary JavaScript execution within the authenticated SOGo webmail session. The issue occurs because SVG content embedded in the description field of an ICS file, with an onrepeat event handler, is insufficiently sanitized before being rendered in the webmail interface. A remote attacker can execute JavaScript in the victim's browser when the malicious calendar invite is viewed.  Successful exploitation may allow mailbox access, email and contact theft, session hijacking, and other actions allowed by an authenticated user."}],"cve":"CVE-2026-8496","ids":[{"system_name":"CERT/CC V Identifier ","text":"VU#487613"}]}],"product_tree":{"branches":[]}}