CVE-2026-57958: Reflected XSS in Mixpost OAuth Callback – Session Hijacking Risk
Mixpost, a social media management platform, contains a reflected cross-site scripting (XSS) vulnerability in its OAuth callback handling. An attacker can craft a malicious callback URL with specially crafted error parameters that, when clicked by an authenticated user, executes arbitrary JavaScript in that user's browser. This can lead to session hijacking or unauthorized actions performed on behalf of the victim. The vulnerability affects Mixpost versions through 2.6.0 and requires no authentication to exploit, though the attack depends on tricking a logged-in user into clicking a malicious link.
Source data · NVD / CISA · public domain
- CVSS
- 3.1 · 6.1 MEDIUM · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- Weaknesses (CWE)
- CWE-79
- Affected products
- 0 configuration(s)
- Published / Modified
- 2026-06-29 / 2026-06-29
NVD description (verbatim)
Mixpost through 2.6.0 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to execute arbitrary JavaScript in authenticated users' browsers by crafting malicious OAuth callback URLs with unsanitized error query parameters. Attackers can exploit the OAuth callback controller's failure to sanitize error parameters before rendering them through Laravel flash messages via the Vue v-html directive to hijack authenticated user sessions or perform unauthorized actions.
3 reference(s) · View on NVD →
SEC.co analysis · AI-assisted, reviewed against source
Technical summary
The vulnerability exists in Mixpost's OAuth callback controller, which fails to sanitize the error query parameter before rendering it through Laravel flash messages. The flash message is subsequently rendered using Vue's v-html directive, which interprets the unsanitized content as HTML and executes embedded JavaScript. An unauthenticated attacker can construct a callback URL containing malicious JavaScript payload in the error parameter. When an authenticated user follows this URL, the payload executes in their browser context with full access to their session and application state. The attack vector is network-based with low complexity; exploitation requires user interaction (clicking the link) but no special privileges.
Business impact
This vulnerability poses a direct risk to Mixpost users' authenticated sessions and data. Attackers could steal session tokens, perform unauthorized posts or account modifications, access connected social media accounts, or exfiltrate sensitive account information. For organizations using Mixpost for social media management, a successful attack could result in unauthorized content publication, brand damage, compromised credentials for connected social platforms, and loss of control over managed accounts. The low barrier to exploitation—requiring only a crafted URL and user click—means this threat is practical to execute at scale.
Affected systems
Mixpost versions up to and including 2.6.0 are vulnerable. The vulnerability affects all deployments of this version, regardless of deployment environment or configuration, as the flaw is in the core OAuth callback handler. Any installation where users may click external links or where attackers can inject links into communications (email, chat, etc.) targeting Mixpost users is at risk.
Exploitability
This vulnerability is straightforward to exploit. An attacker needs only to craft a URL containing JavaScript payload in the error parameter and socially engineer an authenticated Mixpost user into clicking it. No authentication is required on the attacker's part, network access is unrestricted, and the technical complexity is minimal. The primary barrier to exploitation is user interaction—the victim must click the link while logged into Mixpost. This is a practical exploitation scenario in phishing campaigns, malicious link injection, or compromised referral sources. The CVSS score of 6.1 (Medium) reflects the moderate impact potential tempered by the requirement for user interaction.
Remediation
Upgrade Mixpost to a version newer than 2.6.0 that includes proper sanitization of OAuth error parameters. Verify against the Mixpost security advisory for the specific patched version number and release date. Until patching is possible, implement network-based protections such as URL filtering to block known malicious callback domains and security awareness training to reduce the likelihood of users clicking untrusted links.
Patch guidance
Check the official Mixpost repository and security advisories for the patched version that resolves this vulnerability. Apply the update following Mixpost's standard deployment procedures for your installation method. Verify that the patch includes proper input sanitization of OAuth error parameters before rendering. If Mixpost is deployed in a containerized environment, ensure container images are rebuilt with the patched version. Test the update in a non-production environment first to confirm compatibility with your configuration and plugins.
Detection guidance
Monitor access logs for unusual OAuth callback requests containing suspicious characters or HTML/JavaScript syntax in the error parameter. Watch for patterns like %3C, %3E, javascript:, or onerror= in callback URLs. Implement web application firewall (WAF) rules to block callback URLs containing unencoded angle brackets or event handler attributes in query parameters. Check browser console logs on Mixpost instances for unexpected JavaScript execution errors or warnings. Review authentication logs for sessions showing unusual activity immediately after OAuth callback events.
Why prioritize this
While rated CVSS Medium (6.1), this vulnerability merits prompt attention because it enables direct compromise of authenticated user sessions with minimal attacker effort and practical exploitation vectors. The reliance on user interaction is common in real-world attacks and should not be underestimated. Organizations managing important social media accounts through Mixpost face real brand and credential risk. This is not a CISA KEV entry, but the attack surface and impact justify prioritization ahead of lower-impact issues.
Risk score, explained
The CVSS 3.1 score of 6.1 reflects: Network-based attack vector (no special access required), Low complexity (simple URL crafting), No privileges required to exploit, User interaction required (moderate mitigation factor), Changed scope (affects resources beyond the vulnerable component via session hijacking), and Low confidentiality and integrity impacts (compromised sessions and unauthorized actions). The score would be higher were authentication not required on the user end; the user interaction requirement prevents a Critical or High rating despite the practical exploitability.
Frequently asked questions
Can this vulnerability be exploited without the victim clicking a link?
No. The attack requires an authenticated user to click or be redirected to a malicious OAuth callback URL. The vulnerability cannot be exploited passively or without user interaction. However, attackers can use phishing, link injection in emails, or social engineering to lower the friction of this requirement.
Does the attacker need to be authenticated to Mixpost to exploit this?
No. The vulnerability is pre-authentication; the attacker does not need valid Mixpost credentials. They only need to craft a malicious URL and trick a Mixpost user into clicking it. The authenticated user's session is what the attacker hijacks.
What should organizations do immediately if they use Mixpost 2.6.0?
First, identify which version you are running and verify it is 2.6.0 or earlier. Check the official Mixpost security advisories for the patched version number and apply the update as soon as safely possible. In the interim, educate users about not clicking OAuth callback links from untrusted sources and consider implementing URL filtering or WAF rules to block suspicious OAuth callbacks.
Could this vulnerability affect social media accounts connected to Mixpost?
Yes, indirectly. If an attacker compromises a user's Mixpost session, they gain access to all social media accounts and integrations managed through that Mixpost instance. The attacker could then post unauthorized content, modify account settings, or harvest credentials from connected platforms.
This analysis is provided for informational purposes to support security decision-making. The vulnerability details, affected versions, and patch guidance should be verified against official Mixpost security advisories and vendor documentation. No exploit code or detailed weaponization steps are provided. Organizations should conduct their own risk assessment and testing before deploying patches. SEC.co does not guarantee the accuracy of version numbers or patch dates; always consult authoritative vendor sources. Source: NVD (public-domain), retrieved 2026-08-08. Analysis generated by SEC.co (claude-haiku-4-5).
Weaknesses (CWE)
Related vulnerabilities
- CVE-2016-20070MEDIUMPrivilege Escalation & Stored XSS in WordPress Booking Calendar Contact Form 1.0.23
- CVE-2018-25384MEDIUMStored XSS in Wikidforum 2.20 Allows Authenticated Attackers to Inject Malicious Scripts
- CVE-2019-25731MEDIUMStored XSS in Zuz Music 2.1 Contact Form
- CVE-2019-25737MEDIUMStored XSS in Live Chat Unlimited 2.8.3 – Admin Session Compromise
- CVE-2019-25739MEDIUMGigToDo 1.3 Stored XSS Vulnerability in Proposal Descriptions
- CVE-2019-25742MEDIUMStored XSS in Zoner Real Estate WordPress Theme 4.1.1 – Admin Account Compromise Risk
- CVE-2019-25743MEDIUMWordPress Soliloquy Lite 2.5.6 Stored XSS Vulnerability
- CVE-2019-25744MEDIUMWordPress Popup Builder 3.49 Stored XSS Vulnerability – Exploit Prevention & Patch Guide