Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
4.6
Flarum Forum Software: Malicious Email Links in Nicknames
GHSA-3c4m-j3g4-hh25
CVE-2026-30913
GHSA-3c4m-j3g4-hh25
Summary
When using the Nicknames extension in Flarum forum software, a registered user can create a nickname that looks like a link. This can trick email clients into turning the nickname into a clickable link in notification emails, potentially leading recipients to malicious websites. To address this, update the Flarum software and configure the Nicknames extension to prevent this behavior.
What to do
- Update flarum nicknames to version 1.8.3.
- Update flarum flarum/nicknames to version 1.8.3.
Affected software
| Vendor | Product | Affected versions | Fix available |
|---|---|---|---|
| flarum | nicknames | <= 1.8.3 | 1.8.3 |
| flarum | flarum/nicknames | <= 1.8.3 | 1.8.3 |
Original title
Flarum is open-source forum software. When the flarum/nicknames extension is enabled, a registered user can set their nickname to a string that email clients interpret as a hyperlink. The nickname ...
Original description
Flarum is open-source forum software. When the flarum/nicknames extension is enabled, a registered user can set their nickname to a string that email clients interpret as a hyperlink. The nickname is inserted verbatim into plain-text notification emails, and recipients may be misled into visiting attacker-controlled domains.
ghsa CVSS3.1
4.6
Vulnerability type
CWE-79
Cross-site Scripting (XSS)
- https://github.com/flarum/framework/security/advisories/GHSA-3c4m-j3g4-hh25
- https://github.com/flarum/nicknames/commit/4dde99729abdce8f6e2a7437c86e38735fdcc...
- https://github.com/flarum/nicknames/releases/tag/v1.8.3
- https://github.com/advisories/GHSA-3c4m-j3g4-hh25
- https://github.com/flarum/framework Product
- https://github.com/flarum/nicknames/releases/tag/v1.8.
- https://nvd.nist.gov/vuln/detail/CVE-2026-30913
Published: 10 Mar 2026 · Updated: 13 Mar 2026 · First seen: 10 Mar 2026