PT-2026-96170 · Cpan · Email::Sender::Transport::Sendmail
CVE-2026-93012
·
Published
2026-09-21
·
Updated
2026-09-21
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Email::Sender::Transport::Sendmail versions prior to 2.602
Description
On Windows (MSWin32), the software allows arbitrary command execution when sending a message with an envelope address that reaches the shell via the
sendmail pipe function. This occurs because the envelope sender and recipients are concatenated into a single command string passed to a shell through the open() function, whereas other platforms execute sendmail directly using a list form. If no envelope is provided, the system retrieves recipients from the To and Cc headers and the sender from the From header. An attacker controlling any of these header addresses can execute commands with the privileges of the sending process.Recommendations
Update Email::Sender::Transport::Sendmail to version 2.602 or later.
Fix
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Email::Sender::Transport::Sendmail