Lucene search

K
osvGoogleOSV:GHSA-VC6Q-CCJ9-9R89
HistoryApr 05, 2024 - 6:30 a.m.

MailDev Remote Code Execution

2024-04-0506:30:46
Google
osv.dev
6
maildev
remote code execution
content-id header
email attachment
arbitrary code
lib/mailserver.js
routes.js
software

7.5 High

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

15.7%

MailDev 2 through 2.1.0 allows Remote Code Execution via a crafted Content-ID header for an e-mail attachment, leading to lib/mailserver.js writing arbitrary code into the routes.js file.

CPENameOperatorVersion
maildevge2.0.0-beta1
maildevle2.1.0

7.5 High

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

15.7%

Related for OSV:GHSA-VC6Q-CCJ9-9R89