<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Wed, 07 Oct 2026 10:17:14 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-339208</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-339208</link>
      <description>EUVD-2026-339208</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-339208</guid>
    </item>
    <item>
      <title>fkie_cve-2026-45711</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-45711</link>
      <description>&lt;p&gt;Mailpit is an email testing tool and API for developers. Prior to version 1.30.0, the mailpit dump --http &amp;lt;base-url&amp;gt; &amp;lt;out-dir&amp;gt; sub-command downloads every message from a remote Mailpit instance and writes each one as &amp;lt;id&amp;gt;.eml inside the user-supplied output directory. The message ID field is taken verbatim from the JSON response of the remote server and concatenated into the output path with path.Join, which silently normalizes `..` segments. A malicious HTTP server impersonating Mailpit can therefore make mailpit dump write attacker-controlled bytes to any path the running user can write, fully outside the intended output directory. Version 1.30.0 contains a patch.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Mailpit is an email testing tool and API for developers. Prior to version 1.30.0, the mailpit dump --http &amp;lt;base-url&amp;gt; &amp;lt;out-dir&amp;gt; sub-command downloads every message from a remote Mailpit instance and writes each one as &amp;lt;id&amp;gt;.eml inside the user-supplied output directory. The message ID field is taken verbatim from the JSON response of the remote server and concatenated into the output path with path.Join, which silently normalizes `..` segments. A malicious HTTP server impersonating Mailpit can therefore make mailpit dump write attacker-controlled bytes to any path the running user can write, fully outside the intended output directory. Version 1.30.0 contains a patch.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-45711</guid>
    </item>
    <item>
      <title>GHSA-qx5x-85p8-vg4j — Mailpit: Path traversal &amp; arbitrary file write in mailpit dump --http via attacker-controlled message IDs</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-qx5x-85p8-vg4j</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/axllent/mailpit&lt;/p&gt;
&lt;p&gt;### Summary
The mailpit dump --http &amp;lt;base-url&amp;gt; &amp;lt;out-dir&amp;gt; sub-command downloads every message from a remote Mailpit instance and writes each one as &amp;lt;id&amp;gt;.eml inside the user-supplied output directory. The message ID field is taken verbatim from the JSON response of the remote server and concatenated into the output path with path.Join, which silently normalizes .. segments. A malicious HTTP server impersonating Mailpit can therefore make mailpit dump write attacker-controlled bytes to any path the running user can write, fully outside the intended output directory.&lt;/p&gt;
&lt;p&gt;### Details
Anyone who can convince a user to run mailpit dump --http &amp;lt;attacker-url&amp;gt; &amp;lt;dir&amp;gt; (typosquat, phishing tutorial, MITM of a plain-http:// Mailpit, or a compromised internal Mailpit they back up regularly) obtains an arbitrary file write primitive as the dumping user. Realistic post-exploitation includes overwriting init/cron files, shell startup files, CI artifact upload targets, web roots, etc. — anything the dumping user can write to, with attacker-controlled file bytes and a .eml filename suffix.&lt;/p&gt;
&lt;p&gt;### Affected code
[internal/dump/dump.go](https://github.com/axllent/mailpit/blob/develop/internal/dump/dump.go#L118-L155):&lt;/p&gt;
&lt;p&gt;path.Join(&amp;#34;/safe/out/dir&amp;#34;, &amp;#34;../../../../etc/cron.d/payload.eml&amp;#34;) resolves to /etc/cron.d/payload.eml — the .. segments are normalized, not rejected. The remote server controls both m.ID (path) and the body of /api/v1/message/&amp;lt;id&amp;gt;/raw (contents). There is no filepath.Rel(outDir, out) conta…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/axllent/mailpit&lt;/p&gt;
&lt;p&gt;### Summary
The mailpit dump --http &amp;lt;base-url&amp;gt; &amp;lt;out-dir&amp;gt; sub-command downloads every message from a remote Mailpit instance and writes each one as &amp;lt;id&amp;gt;.eml inside the user-supplied output directory. The message ID field is taken verbatim from the JSON response of the remote server and concatenated into the output path with path.Join, which silently normalizes .. segments. A malicious HTTP server impersonating Mailpit can therefore make mailpit dump write attacker-controlled bytes to any path the running user can write, fully outside the intended output directory.&lt;/p&gt;
&lt;p&gt;### Details
Anyone who can convince a user to run mailpit dump --http &amp;lt;attacker-url&amp;gt; &amp;lt;dir&amp;gt; (typosquat, phishing tutorial, MITM of a plain-http:// Mailpit, or a compromised internal Mailpit they back up regularly) obtains an arbitrary file write primitive as the dumping user. Realistic post-exploitation includes overwriting init/cron files, shell startup files, CI artifact upload targets, web roots, etc. — anything the dumping user can write to, with attacker-controlled file bytes and a .eml filename suffix.&lt;/p&gt;
&lt;p&gt;### Affected code
[internal/dump/dump.go](https://github.com/axllent/mailpit/blob/develop/internal/dump/dump.go#L118-L155):&lt;/p&gt;
&lt;p&gt;path.Join(&amp;#34;/safe/out/dir&amp;#34;, &amp;#34;../../../../etc/cron.d/payload.eml&amp;#34;) resolves to /etc/cron.d/payload.eml — the .. segments are normalized, not rejected. The remote server controls both m.ID (path) and the body of /api/v1/message/&amp;lt;id&amp;gt;/raw (contents). There is no filepath.Rel(outDir, out) conta…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-qx5x-85p8-vg4j</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-1558 — MailPit: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1558</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in MailPit ausnutzen, um Dateien zu manipulieren, vertrauliche Informationen offenzulegen oder einen Denial-of-Service-Zustand zu verursachen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in MailPit ausnutzen, um Dateien zu manipulieren, vertrauliche Informationen offenzulegen oder einen Denial-of-Service-Zustand zu verursachen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1558</guid>
    </item>
  </channel>
</rss>
