Dossier
CVE-2026-41241
Coverage of CVE-2026-41241 in the Nexus archive.
- How to guarantee a speaker gig: Hack the system. Literally
A security researcher exploited a stored XSS vulnerability (CVE-2026-41241) in pretalx, a conference management tool, to auto-apply for and secure 40 speaker slots. The flaw allowed injecting malicious code via searchable fields, enabling unauthorized actions in the organizer interface. The vulnerability was patched in pretalx 2026.1.0, and the researcher validated findings responsibly without harming live systems.