<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Rainloop 1.16 (current) has an unpatched security bug]]></title><description><![CDATA[<p dir="auto">As per <a href="https://thehackernews.com/2022/04/unpatched-bug-in-rainloop-webmail-could.html" target="_blank" rel="noopener noreferrer nofollow ugc">https://thehackernews.com/2022/04/unpatched-bug-in-rainloop-webmail-could.html</a></p>
<blockquote>
<p dir="auto">An unpatched high-severity security flaw has been disclosed in the open-source RainLoop web-based email client that could be weaponized to siphon emails from victims' inboxes.</p>
<p dir="auto">"The code vulnerability  can be easily exploited by an attacker by sending a malicious email to a victim that uses RainLoop as a mail client," SonarSource security researcher Simon Scannell said in a report published this week.</p>
<p dir="auto">"When the email is viewed by the victim, the attacker gains full control over the session of the victim and can steal any of their emails, including those that contain highly sensitive information such as passwords, documents, and password reset links."</p>
</blockquote>
<p dir="auto">On Yunohost they recommend switching to Snappymail (already in the appstore): <a href="https://forum.yunohost.org/t/security-rainloop-suffers-a-security-bug/19579" target="_blank" rel="noopener noreferrer nofollow ugc">https://forum.yunohost.org/t/security-rainloop-suffers-a-security-bug/19579</a></p>
]]></description><link>https://forum.cloudron.io/topic/6858/rainloop-1-16-current-has-an-unpatched-security-bug</link><generator>RSS for Node</generator><lastBuildDate>Thu, 11 Jun 2026 07:37:29 GMT</lastBuildDate><atom:link href="https://forum.cloudron.io/topic/6858.rss" rel="self" type="application/rss+xml"/><pubDate>Fri, 22 Apr 2022 22:11:44 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to Rainloop 1.16 (current) has an unpatched security bug on Sun, 24 Apr 2022 20:18:34 GMT]]></title><description><![CDATA[<p dir="auto">I have pushed a new package with the patch.</p>
]]></description><link>https://forum.cloudron.io/post/46578</link><guid isPermaLink="true">https://forum.cloudron.io/post/46578</guid><dc:creator><![CDATA[girish]]></dc:creator><pubDate>Sun, 24 Apr 2022 20:18:34 GMT</pubDate></item><item><title><![CDATA[Reply to Rainloop 1.16 (current) has an unpatched security bug on Sun, 24 Apr 2022 19:17:48 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/necrevistonnezr" aria-label="Profile: necrevistonnezr">@<bdi>necrevistonnezr</bdi></a> thanks for reporting. Making a new package with the patch at <a href="https://blog.sonarsource.com/rainloop-emails-at-risk-due-to-code-flaw" target="_blank" rel="noopener noreferrer nofollow ugc">https://blog.sonarsource.com/rainloop-emails-at-risk-due-to-code-flaw</a></p>
]]></description><link>https://forum.cloudron.io/post/46574</link><guid isPermaLink="true">https://forum.cloudron.io/post/46574</guid><dc:creator><![CDATA[girish]]></dc:creator><pubDate>Sun, 24 Apr 2022 19:17:48 GMT</pubDate></item></channel></rss>