Junglewise Threat Intelligence

CVE-2026-45068: Symfony Mailer argument injection in SendmailTransport

CVE-2026-45068 · Severity: medium · CVSS 4 · Published 2026-07-14

Technologies: Symfony. Vendors: Symfony.

Executive brief

Symfony is a popular PHP framework used to build web applications. A security flaw in its email-sending component could allow an attacker to manipulate the underlying mail server by providing a specially crafted email address. This could lead to unauthorized actions on the server, such as modifying how emails are sent or potentially accessing sensitive system information.

Technical details

An argument injection vulnerability exists in Symfony's Mailer component, specifically within the SendmailTransport class when used in '-t' mode. The component appended recipient addresses to the sendmail command line without the '--' end-of-options separator. This allows an attacker who can control a recipient email address to inject arbitrary sendmail command-line flags by providing an address starting with a dash (e.g., '-O'). This is classified as CWE-88. The issue is resolved in versions 5.4.52, 6.4.40, 7.4.12, and 8.0.12 by adding the separator and rejecting addresses starting with a dash.

Affected products

  • symfony symfony < 5.4.52, >= 6.0.0-BETA1 < 6.4.40, >= 7.0.0-BETA1 < 7.4.12, >= 8.0.0-BETA1 < 8.0.12
  • symfony mailer < 5.4.52, >= 6.0.0-BETA1 < 6.4.40, >= 7.0.0-BETA1 < 7.4.12, >= 8.0.0-BETA1 < 8.0.12

Timeline

  • 2026-07-14: advisory
  • 2026-05-20: patched

References