Answer in brief
CVE-2026-104083 records a Medium severity (CVSS 5.3) vulnerability in SmarterMail < Build 9777 Stored Mutation XSS via MathML Foreign Content. The current sources do not mark it as known exploited. The current feed maps Smartertools/Smartermail (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
CVSS is 5.3. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Smartertools/Smartermail (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Smartertools/Smartermailgeneric | >=0 <Build 9777 | Build 9777, Build |
Published upstream
Oct 9, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Oct 9, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Oct 9, 2026
SmarterMail before build 9777 contains a stored mutation cross-site scripting vulnerability that allows remote attackers to inject executable script by placing payloads inside a <style> element nested within MathML foreign content (<math><mtext><mglyph>), which the custom HTML sanitizer treats as inert CDATA text but browsers reparse as live markup. Attackers can deliver a crafted calendar (iCal) message containing an <img src=x onerror=...> payload that executes automatically in the recipient's webmail session at /interface/message-iframe when the message is opened, enabling script execution and data exfiltration unconstrained by the interface's permissive Content-Security-Policy.
Quoted source text, attributed separately from HOL analysis.