PT-2026-41966 · Mailpit · Mailpit

CVE-2026-45711

·

Published

2026-05-19

·

Updated

2026-07-30

CVSS v3.1

8.2

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L
Name of the Vulnerable Software and Affected Versions Mailpit (affected versions not specified)
Description The dump --http sub-command allows an arbitrary file write via path traversal. When downloading messages from a remote server, the tool uses the message ID from the JSON response to construct the output file path using path.Join. Because this function normalizes .. segments without validation, a malicious server can provide a crafted ID to write files outside the intended output directory. This can be exploited if a user is convinced to run the command against a malicious URL, potentially allowing the attacker to overwrite sensitive files such as cron jobs, shell startup files, or CI artifacts, which may lead to code execution.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-45711
GHSA-QX5X-85P8-VG4J
GO-2026-5599
OPENSUSE-SU-2026:21483-1

Affected Products

Mailpit