PT-2026-85250 · Unknown · Parsedmarc
CVSS v4.0
6.3
Medium
| Vector | AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
parsedmarc versions 9.0.6 through 11.0.0
Description
The software writes forensic report sample files using an output path derived from the email subject. If the subject consists entirely of path traversal sequences (sequences used to access files and directories outside the intended folder), the filename sanitization function returns an empty string. This triggers a fallback to the raw unsanitized subject, allowing a file to be written outside the designated samples directory. An attacker can exploit this by sending a crafted Subject in a forensic failure report to write a dot-prefixed file with controlled content to an ancestor directory of the configured samples output path. This requires that file output for forensic report samples be enabled.
Recommendations
Update parsedmarc to version 11.0.1 or later.
Disable file output for forensic report samples to mitigate the risk of exploitation.
Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Parsedmarc