PT-2026-96170 · Cpan · Email::Sender::Transport::Sendmail

CVE-2026-93012

·

Published

2026-09-21

·

Updated

2026-09-21

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Email::Sender::Transport::Sendmail versions prior to 2.602
Description On Windows (MSWin32), the software allows arbitrary command execution when sending a message with an envelope address that reaches the shell via the sendmail pipe function. This occurs because the envelope sender and recipients are concatenated into a single command string passed to a shell through the open() function, whereas other platforms execute sendmail directly using a list form. If no envelope is provided, the system retrieves recipients from the To and Cc headers and the sender from the From header. An attacker controlling any of these header addresses can execute commands with the privileges of the sending process.
Recommendations Update Email::Sender::Transport::Sendmail to version 2.602 or later.

Fix

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-93012

Affected Products

Email::Sender::Transport::Sendmail