Junglewise Threat Intelligence

CVE-2026-29780: PYSEC-2026-2148 - eml_parser serves as a python module for parsing eml files and returning various information found in the e-mail as well as computed informa

CVE-2026-29780 · Severity: low · CVSS 3.1 · Published 2026-03-07

Technologies: eml-parser (PyPI), GOVCERT-LU Eml Parser. Vendors: PyPI, GOVCERT-LU.

Executive brief

The eml_parser library includes an example script for extracting email attachments that fails to validate attachment filenames before writing them to disk. An attacker can craft a malicious email with a specially-crafted filename (e.g., "../../../etc/cron.d/backdoor") to write files outside the intended directory, potentially enabling code execution or system compromise through injection into sensitive system locations.

Technical details

The vulnerability is a path traversal flaw (CWE-22) in the official example script examples/recursively_extract_attachments.py (lines 61–64). Attachment filenames extracted from email Content-Disposition headers are directly used in pathlib.Path construction without sanitization or normalization. An attacker-controlled filename containing traversal sequences (../) can escape the target output directory. The attack requires local execution of the vulnerable script and user interaction (running the script against a crafted email), but no elevated privileges. An attacker can write arbitrary files within the execution context's filesystem permissions, potentially leading to cron job injection, web shell upload, or SSH key injection. The vulnerability was patched in version 2.0.1 with proper path normalization and boundary validation using os.path.basename() and Path.is_relative_to().

Affected products

  • GOVCERT-LU eml_parser before 2.0.1

Timeline

  • 2026-03-05: disclosed
  • 2026-03-05: patched: Version 2.0.1 released with fix
  • 2026-03-07: advisory: NVD published CVE-2026-29780

References

Related threats