Medium severity4.3NVD Advisory· Published Mar 27, 2026· Updated Apr 10, 2026
CVE-2026-33284
CVE-2026-33284
Description
GlobaLeaks is free and open-source whistleblowing software. Prior to version 5.0.89, the /api/support endpoint of GlobaLeaks performs minimal validation on user-submitted support requests. As a result, arbitrary URLs can be included in support emails sent to administrators. Version 5.0.89 patches the issue.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- github.com/globaleaks/globaleaks-whistleblowing-software/security/advisories/GHSA-84wr-q36q-wqhvnvdExploitMitigationVendor Advisory
News mentions
0No linked articles in our index yet.