PT-2026-41966 · Mailpit · Mailpit
CVE-2026-45711
·
Published
2026-05-19
·
Updated
2026-07-30
CVSS v3.1
8.2
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L |
Name of the Vulnerable Software and Affected Versions
Mailpit (affected versions not specified)
Description
The
dump --http sub-command allows an arbitrary file write via path traversal. When downloading messages from a remote server, the tool uses the message ID from the JSON response to construct the output file path using path.Join. Because this function normalizes .. segments without validation, a malicious server can provide a crafted ID to write files outside the intended output directory. This can be exploited if a user is convinced to run the command against a malicious URL, potentially allowing the attacker to overwrite sensitive files such as cron jobs, shell startup files, or CI artifacts, which may lead to code execution.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Mailpit