PatchSiren

django-helpdesk CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM django-helpdesk CVE published 2026-08-13

CVE-2026-73531

CVE-2026-73531 is a stored cross-site scripting vulnerability in django-helpdesk before version 2.3.3. The vulnerability allows unauthenticated attackers to inject arbitrary JavaScript by submitting HTML-formatted email messages or uploading .html/.htm file attachments through public ticket submission channels. Attackers can exploit the lack of sanitization and Content-Disposition headers at the attachmen [truncated]