Path Traversal Vulnerability in Mailpit Email Testing Tool by Axllent
CVE-2026-45711

5.9MEDIUM

Key Information:

Vendor

Axllent

Status
Vendor
CVE Published:
20 July 2026

What is CVE-2026-45711?

Mailpit, an email testing tool designed for developers, has a path traversal vulnerability prior to version 1.30.0. This issue arises from the mailpit dump --http command, which can be exploited by a malicious HTTP server impersonating Mailpit. The tool improperly constructs file paths by using the message ID from the remote server's JSON response, which may include unnecessary normalization of path segments. As a result, attackers can write files outside the specified output directory, potentially leading to unauthorized access to sensitive information. To mitigate this risk, users should upgrade to version 1.30.0 or later, where the vulnerability has been addressed.

Affected Version(s)

mailpit < 1.30.0

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.