PT-2026-85250 · Unknown · Parsedmarc

·

CVE-2026-82521

·

Published

2026-09-03

·

Updated

2026-09-03

CVSS v4.0

6.3

Medium

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions parsedmarc versions 9.0.6 through 11.0.0
Description The software writes forensic report sample files using an output path derived from the email subject. If the subject consists entirely of path traversal sequences (sequences used to access files and directories outside the intended folder), the filename sanitization function returns an empty string. This triggers a fallback to the raw unsanitized subject, allowing a file to be written outside the designated samples directory. An attacker can exploit this by sending a crafted Subject in a forensic failure report to write a dot-prefixed file with controlled content to an ancestor directory of the configured samples output path. This requires that file output for forensic report samples be enabled.
Recommendations Update parsedmarc to version 11.0.1 or later. Disable file output for forensic report samples to mitigate the risk of exploitation.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-82521
GHSA-C284-W5M6-JHJM

Affected Products

Parsedmarc