Cross-Site WebSocket Hijacking Vulnerability in Mailpit Email Testing Tool
CVE-2026-22689
6.5MEDIUM
What is CVE-2026-22689?
The Mailpit email testing tool, prior to version 1.28.2, is susceptible to a Cross-Site WebSocket Hijacking vulnerability due to improper configuration of its WebSocket server. This flaw allows attackers to exploit the lack of Origin header validation. By hosting a malicious website, an attacker can initiate a WebSocket connection to a developer's local Mailpit instance. As a result, sensitive information such as email contents, headers, and server statistics can be intercepted in real-time, posing significant security risks for developers using Mailpit in their testing environment. This issue has been addressed in version 1.28.2.
Affected Version(s)
mailpit < 1.28.2
