Executive brief
EGroupware is a collaboration software suite used for email, calendaring, and document management. A security flaw in the email composition tool allows an authorized user to trick the server into reading sensitive files from its own storage. This could lead to the exposure of system passwords, database credentials, or private encryption keys, potentially compromising the entire server.
Technical details
A Local File Inclusion (LFI) vulnerability exists in EGroupware's mail composition logic within `api/src/Mail.php`. The application fails to properly validate URI schemes when processing image URLs in HTML email bodies. Specifically, the check `!str_starts_with($myUrl, 'http')` incorrectly permits `file://` URIs. When a user includes an `<img>` tag with a `file://` source, the server uses `file_get_contents()` to read the specified local file and attaches its contents as an inline MIME part in the outgoing email. This allows an authenticated attacker to exfiltrate sensitive files like `/etc/passwd` or configuration files. The issue is resolved in versions 26.5.20260507 and 23.1.20260601.
Affected products
- EGroupware EGroupware >= 26.0.20251208, < 26.5.20260507; < 23.1.20260601
Timeline
- 2026-07-07: advisory: GitHub Advisory GHSA-c8m7-r2jv-rw63 published
- 2026-07-07: disclosed: Vulnerability disclosed with CVE-2026-45016