Advisories for Npm/@Tutao/Tutanota-Utils package

2025

Tuta Mail has DOM attribute and CSS injection in its Contact Viewer feature

Users importing contacts from untrusted sources. Specifically crafted contact data can lead to some of DOM modifications for the link button next to the field e.g. the link address can be overriden. CSS can be manipulated to give the button arbitrary look and change it's size so that any click on the screen would lead to the specified URL. Modifying event listeners does not seem to be possible so no …