Junglewise Threat Intelligence

CVE-2026-13014: Thales CERT Suspicious path traversal and RCE via Matryoshka Mail

CVE-2026-13014 · Severity: info · CVSS 9.2 · Published 2026-07-13

Executive brief

Thales CERT Suspicious is an AI-powered platform used by security teams to analyze and report phishing emails and malicious files. A critical vulnerability allows an unauthenticated remote attacker to take full control of the application, potentially leading to the theft of sensitive security secrets, permanent service disruption, or the execution of malicious code with administrative privileges. This could allow an attacker to pivot from a suspicious email submission to a full compromise of the analysis environment.

Technical details

A vulnerability dubbed 'Matryoshka Mail' exists in the Thales CERT 'Suspicious' application (versions 1.3.4 and prior) due to improper limitation of pathnames and external control of file paths (CWE-22, CWE-73). The flaw involves a nested attachment traversal mechanism that allows a remote, unauthenticated attacker to overwrite writable application files, including Python modules, configuration files, and cron inputs. Successful exploitation can lead to arbitrary code execution (CWE-94) as root within the Django application container, persistent denial of service, and compromise of application secrets. The issue is addressed in version 1.3.5.

Affected products

  • Thales Group Suspicious <= 1.3.4

Timeline

  • 2026-07-13: advisory: GitHub Security Advisory GHSA-x85x-9mrm-wwvp published
  • 2026-07-13: disclosed: CVE-2026-13014 published to NVD
  • 2026-07-13: patched: Version 1.3.5 released to address the vulnerability

References