Junglewise Threat Intelligence

CVE-2026-58451: Horde IMP path traversal in lib/Compose.php

CVE-2026-58451 · Severity: medium · CVSS 6.5 · Published 2026-07-01

Executive brief

Horde IMP is a popular webmail application used to access email accounts. A security flaw in its message composition feature allows an attacker with a valid account to steal sensitive files from the underlying server. By sending a specially crafted email, the attacker can force the server to include private system files as attachments in the outgoing message. This could also be triggered against legitimate users via a malicious link (CSRF).

Technical details

A path traversal vulnerability exists in the IMP_Compose::_convertToRelated() function within lib/Compose.php. The application uses stripos() to validate that image source URLs in HTML emails start with a specific CKEditor path prefix, but it fails to properly sanitize the remainder of the path. An attacker can append traversal sequences (e.g., ../) after the valid prefix to bypass the check. This causes file_get_contents() to read arbitrary files from the server, which are then attached as MIME parts to the outgoing email. While primarily requiring authentication, the flaw is also exploitable via Cross-Site Request Forgery (CSRF) against an active session. The issue is resolved in version 7.0.1 by implementing stricter prefix validation and realpath() containment checks.

Affected products

  • Horde IMP < 7.0.1

Timeline

  • 2026-07-01: disclosed
  • 2026-07-01: patched: Fixed in version 7.0.1
  • 2026-07-01: advisory

References

Related threats