CVE-2026-59239: Roskus Prospero Flow CRM
High severity, CVSS 8.6. EPSS: 0.7% chance of exploitation in the next 30 days.
Stored Cross-site Scripting (CWE-79) in the email module in Roskus Prospero Flow CRM before 5.4.4 allows a remote, authenticated low-privileged user to execute arbitrary JavaScript in another user's browser, including administrators, leading to session compromise and account takeover, via a payload stored in an email body that is persisted without sanitization and rendered unescaped with {!! $email->body !!} when the recipient opens the message.
Affected products
- Roskus Prospero Flow CRM: from 1.0.0, before 5.4.4 (fixed in 5.4.4)
Published 2026-07-27. Last modified 2026-09-01.