CVE-2026-49996 | Freedom of the Press Foundation SecureDrop Client up to 1.3.0 securedrop-proxy cross-domain policy
A vulnerability has been found in Freedom of the Press Foundation SecureDrop Client up to 1.3.0 and classified as problematic. The impacted element is an unknown function of the component securedrop-proxy. The manipulation leads to permissive cross-domain policy with untrusted domains.
This vulnerability is documented as CVE-2026-49996. The attack can be initiated remotely. There is not any exploit available.
The affected component should be upgraded.VulDB Recent EntriesRead More