PT-2026-49717 · Forem · Forem

CVE-2026-48780

·

Published

2026-06-16

·

Updated

2026-06-16

CVSS v3.1

8.2

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions Forem versions prior to commit a2ab6d4
Description An issue exists where a maliciously crafted email address can be used to bypass domain allowlist or denylist restrictions. This allows an attacker to gain unauthorized access to invite-only deployments.
Recommendations Update to the version containing commit a2ab6d4. As a temporary workaround, use SMTP servers or email delivery providers that drop or refuse to send maliciously crafted email addresses.

Exploit

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-48780
GHSA-3G4H-9H37-MPX6

Affected Products

Forem