---
id: CVE-2026-97735
title: >-
  ITFlow before 26.08 allows SVG attachments in the ticket email parser
  (cron/ticket_email_parser.php) for email messages that may arrive over SMTP
  from arbitrary senders.
summary: >-
  ITFlow before 26.08 allows SVG attachments in the ticket email parser
  (cron/ticket_email_parser.php) for email messages that may arrive over SMTP
  from arbitrary senders.
severity: high
cvss: 8
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:N'
cwe:
  - CWE-79
vendor: ITFlow
product: ITFlow
affected:
  - ITFlow < 26.08
published: '2026-09-25'
updated: '2026-09-25'
sourceUpdated: '2026-09-25T14:17:26.530'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-97735'
references:
  - url: >-
      https://github.com/itflow-org/itflow/commit/16000efcf7f7c833aae9f8da22d2a82df21a49c0
    label: cve@mitre.org
  - url: >-
      https://github.com/itflow-org/itflow/security/advisories/GHSA-89fw-w69c-vghj
    label: cve@mitre.org
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-09-25T13:54:20.076459Z'
epss: 0.00254
epssPercentile: 0.15097
ingestedAt: '2026-09-25T03:58:52.655Z'
---

## Overview

ITFlow before 26.08 allows SVG attachments in the ticket email parser (cron/ticket_email_parser.php) for email messages that may arrive over SMTP from arbitrary senders.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
