Vulnerability Management

Pretalx vulnerability allows account takeover and admin demotion

(Adobe Stock)

A critical stored cross-site scripting (XSS) vulnerability has been discovered in pretalx, a widely-used open-source software for managing conference submissions and scheduling. This high-severity flaw, tracked as CVE-2026-41241 and discovered by Elad Meged, a founding engineer and security researcher at Novee, allows attackers to hijack organizer accounts without user interaction, based on information published by HackRead.

The vulnerability, with a CVSS score of 8.7, can be exploited with low privileges and complexity. Attackers can inject malicious HTML or JavaScript into the organizer-side search bar dropdown. A chained exploit allows bypassing Content Security Policies by uploading a JavaScript payload disguised as presentation material. When an organizer uses the search function, the malicious code executes within the organizer's session, enabling account hijacking and data theft. A secondary attack vector, requiring no JavaScript, can demote administrators by triggering a superuser-demotion endpoint via an image tag in a submission title.

Novee researchers suggest AI agents could automate this attack, targeting numerous conferences simultaneously for a high success rate. Traditional security tools struggle to detect these chained exploits. The pretalx team has released a patch in version v2026.1.0.

Source: HackRead

Related Events

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds