{"id":"CVE-2026-97735","published":"2026-09-25T04:17:50.763","lastModified":"2026-09-25T14:17:26.530","description":"ITFlow before 26.08 allows SVG attachments in the ticket email parser (cron/ticket_email_parser.php) for email messages that may arrive over SMTP from arbitrary senders.","cvssScore":8,"cvssSeverity":"HIGH","cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:N","cwes":["CWE-79"],"vendors":[],"products":[],"references":[{"url":"https://github.com/itflow-org/itflow/commit/16000efcf7f7c833aae9f8da22d2a82df21a49c0","tags":[]},{"url":"https://github.com/itflow-org/itflow/security/advisories/GHSA-89fw-w69c-vghj","tags":[]}],"exploitRefs":[{"url":"https://github.com/itflow-org/itflow/commit/16000efcf7f7c833aae9f8da22d2a82df21a49c0","tags":[]},{"url":"https://github.com/itflow-org/itflow/security/advisories/GHSA-89fw-w69c-vghj","tags":[]}],"hasPoc":true,"ai":null}