Skip to content
The Nexus
SECURITYMay 27 · 12:00 UTCTHE REGISTER

How to guarantee a speaker gig: Hack the system. Literally

A security researcher exploited a stored XSS vulnerability (CVE-2026-41241) in pretalx, a conference management tool, to auto-apply for and secure 40 speaker slots. The flaw allowed injecting malicious code via searchable fields, enabling unauthorized actions in the organizer interface. The vulnerability was patched in pretalx 2026.1.0, and the researcher validated findings responsibly without harming live systems.

Nexus surfaces and summarizes. The full story lives at the source.

Mentioned
Spot something wrong with this article?Report a problem →
Forward this
Related Signal

Adjacent reporting