Executive brief
Forem is an open-source platform used to build online communities. A security flaw allows attackers to use specially formatted email addresses to bypass domain restrictions, such as allowlists or denylists. This could allow unauthorized individuals to gain access to private, invite-only community deployments, potentially exposing sensitive member data.
Technical details
An improper authentication vulnerability (CWE-287) exists in Forem due to insufficient validation of email addresses during the registration or invitation process. Specifically, the application failed to properly handle 'encoded-word' syntax in email addresses, which could be used to bypass domain-based access controls (allowlists/denylists). An unauthenticated remote attacker can exploit this by providing a maliciously crafted email address to gain unauthorized access to invite-only deployments. The vulnerability was addressed in commit a2ab6d4 by implementing a validation check that rejects email addresses containing encoded-word syntax.
Affected products
- Forem Forem All versions before commit a2ab6d4
Timeline
- 2026-05-26: patched: Fix committed to repository
- 2026-06-16: disclosed: NVD publication date