Executive brief
Mailpit is an email testing tool used by developers to capture and view outgoing emails during software development. A security flaw in its data export command allows a malicious server to trick the tool into writing files to unauthorized locations on the user's computer. This could allow an attacker to overwrite sensitive system files, potentially leading to system instability or unauthorized access if the user connects to a compromised or untrusted Mailpit instance.
Technical details
A path traversal vulnerability exists in the 'mailpit dump --http' sub-command of Mailpit prior to version 1.30.0. The tool downloads messages from a remote instance and uses the message ID field from the server's JSON response to construct local filenames using 'path.Join'. Because 'path.Join' silently normalizes '..' segments and the tool lacks a 'filepath.Rel' containment check, a malicious server can provide IDs containing traversal sequences. This allows an attacker to write arbitrary bytes (with a .eml extension) to any path the executing user has write permissions for. Exploitation requires the user to connect the tool to a malicious or compromised Mailpit-compatible HTTP server. The issue is patched in version 1.30.0.
Affected products
- axllent Mailpit < 1.30.0
Timeline
- 2026-05-14: patched: Version 1.30.0 released with fix.
- 2026-07-20: disclosed: CVE-2026-45711 published.