PatchSiren

swoosh CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

LOW swoosh CVE published 2026-07-06

CVE-2026-54893

CVE-2026-54893 is a low-severity vulnerability in the Microsoft Graph adapter of Swoosh, allowing URL path injection due to improper handling of user-influenced input. This issue affects Swoosh versions from 1.12.0 before 1.26.3. Applications using a fixed, trusted 'from' address are not affected. The vulnerability can lead to potential unauthorized Microsoft Graph API requests and possible elevation of p [truncated]