A single speaker submission can reach across many Pretalx conferences because organizers later search that content in their own browsers. That turns a stored XSS bug into an organizer takeover path, not a normal one-site script injection issue.
Novee says CVE-2026-41241 affects Pretalx, the open source CFP platform used by many technical conferences. The flaw is patched in Pretalx 2026.1.0, and the reported impact includes account takeover and manipulated talk acceptance decisions when an organizer searches a booby-trapped submission.
The risk is broader than one conference site because the same codebase and search flow are shared across deployments. Any browser workflow that lets admin-side users search, preview, or review attacker text creates the same trust break.