Pretalx Email Injection Vulnerability via Unescaped User-Controlled Placeholders

Vulnerability

A vulnerability in Pretalx prior to version 2026.1.0 allows unauthenticated attackers to send arbitrary HTML-rendered emails from the application's configured sender address. This is achieved by embedding malformed HTML or markdown link syntax into user-controlled template placeholders, such as the account display name. The vulnerability can be exploited through the password-reset process: an attacker can register an account with a malicious name, input a victim's email address, and initiate a password reset. The email sent will appear to come from a legitimate source and will pass SPF, DKIM, and DMARC validation, creating a phishing opportunity. This issue also affects other email templates that use user-controlled placeholders, including organizer-triggered notifications.

Impact

Exploitation of this vulnerability allows for email injection, where an attacker can send phishing emails that appear to come from a legitimate source within the Pretalx application.

Remediation

Users can upgrade to Pretalx version 2026.1.0 or later to address this vulnerability.

Added: Apr 24, 2026, 8:50 PM
Updated: Apr 24, 2026, 8:50 PM

Vulnerability Rating

Custom Algorithm
spread
1.0
impact
0.6
exploitability
5.4
remediation
7.7
relevance
6.3
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.