CVE-2026-41241Disclosure(pretalx / pretalx)

LOWCVSS 5.4 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch pretalx pretalx systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

pretalx is a conference planning tool. Prior to 2026.1.0, The organiser search in the pretalx backend rendered submission titles, speaker display names, and user names/emails into the result dropdown using innerHTML string interpolation. Any user who controls one of those fields (which includes any registered user whose display name is looked up by an administrator) could include HTML or JavaScript that would execute in an organiser's browser when the organiser's search query matched the malicious record. This vulnerability is fixed in 2026.1.0.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • pretalx

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 5 signals
  • Disclosure: 3 classified signals
  • Peaked 1d ago at 3 mentions (2026-05-28); latest day: 1
  • 5 total mentions across 3 days

Affected systems

Vendors
Products
pretalx

Deep dive

Activity timeline5 mentions / 3d
01223Mentions · 2026-04-23: 1Mentions · 2026-05-28: 3Mentions · 2026-06-02: 1Patch / Workaround · 2026-05-28: 2Patch / Workaround · 2026-06-02: 1Technical Details · 2026-04-23: 1Technical Details · 2026-05-28: 3Technical Details · 2026-06-02: 104-2305-2806-02
Signal classification2 categories
Disclosure
360.0%
Patch
240.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-04-231
Disclosure1
2026-05-283
Disclosure2Patch1
2026-06-021
Patch1
Full discourse5 posts
  • Cyber News Live@cybernewslive
    Patch

    A serious security flaw (CVE-2026-41241) in pretalx — open-source software used to run conference submission and scheduling systems — lets any registered user hijack an organiser's account without the organiser clicking anything. The attack works by hiding malicious code inside a presentation submission title; when an organiser searches for talks, the code runs silently and can steal their session, accept talks automatically, or permanently strip their admin access. The flaw has been patched in pretalx version v2026.1.0, released 27 May 2026. If you run or organise a conference using pretalx, update to v2026.1.0 immediately — go to your server's admin panel or package manager and confirm the version number before accepting any new submissions. 🔥 #CyberNewsLive https://hackread.com/zero-click-pretalx-xss-hackers-hijack-conference-accounts/

    Post summary

    CVE-2026-41241 is a zero‑click XSS vulnerability that lets a registered user hijack an organiser’s account via a malicious presentation title; pretalx has released patch v2026.1.0, and users are urged to update immediately.

    0000057
    2.1K followersView on X
  • UNDERCODE NEWS@UndercodeNews
    Disclosure

    🚨 #CVE-2026-41241: Pretalx Stored XSS Flaw Allowed Speakers to Hijack Organizer Sessions + Video -Fact Checker: ✅: 2 ❌: 0 || 2/2 http://undercodenews.com/cve-2026-41241-pretalx-stored-xss-flaw-allowed-speakers-to-hijack-organizer-sessions-video/

    Post summary

    The message announces CVE‑2026‑41241, a stored XSS vulnerability in Pretalx that lets speakers hijack organizer sessions and videos, without indicating active exploitation or mitigation details.

    0000032
    866 followersView on X
  • Cyber News Live@cybernewslive
    Patch

    A security researcher found a flaw (CVE-2026-41241) in pretalx — open source software used by dozens of tech conferences to manage speaker submissions — that let anyone inject hidden code into the system by simply filling in a submission form. When a conference organiser searched for that entry, the hidden code ran silently in their browser, handing an attacker full control of the organiser's account. The researcher used it to get accepted as a speaker at 40 conferences simultaneously, but did not run a live attack on real systems. The flaw has been fixed in pretalx version 2026.1.0 — but the real risk is that a compromised conference platform becomes a launchpad for convincing phishing attacks against speakers, sponsors, and attendees who trust emails appearing to come from a legitimate event. ☠️ #CyberNewsLive https://theregister.com/security/2026/05/27/pretalx-xss-flaw-exposed-conference-cfp-systems/5246598

    Post summary

    The article reports a discovered XSS vulnerability in pretalx that allows code injection via conference submission forms and notes the issue has been patched in version 2026.1.0.

    0000063
    2.1K followersView on X
  • Cybersecurity News Everyday@TweetThreatNews
    Disclosure

    CVE-2026-41241 in Pretalx exposed a stored XSS flaw that let registered speakers run JavaScript in organizers' browsers during submission searches. Patched in 2026.1.0. #Pretalx #CVE202641241 #XSS https://ift.tt/XSj9ks0

    Post summary

    CVE‑2026‑41241 is a disclosed stored XSS flaw in Pretalx, patched in version 2026.1.0; the post provides technical details but no PoC, exploit code, or evidence of active exploitation.

    00000109
    4.3K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-41241 pretalx is a conference planning tool. Prior to 2026.1.0, The organiser search in the pretalx backend rendered submission titles, speaker display names, and user name… https://www.cve.org/CVERecord?id=CVE-2026-41241

    Post summary

    The CVE refers to an information‑disclosure vulnerability in Pretalx pre‑2026.1.0, with no evidence of a PoC, exploit, active exploitation, patch, or debunking.

    0000094
    57.2K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apppretalxpretalx---

Explore more