• Sources: GitHub advisory GHSA-8r62-w5wh-fc5m, Mailpit 1.30.6 release
  • Summary: The advisory publishes the affected range as Mailpit 1.29.0 through 1.30.5, patched in 1.30.6. The origin check is applied against the raw request URI while the router dispatches on the decoded path, so a percent-encoded path reaches the WebSocket endpoint without the origin check matching it, and a page on any other origin can open the socket in the visitor's browser and receive messages as they arrive. The advisory tracks this as CVE-2026-67448 and records it as a regression of CVE-2026-22689, fixed in commit 6f1f4f3 on 2026-01-10 and shipped in 1.28.2, then reintroduced in commit a63bcd9 on 2026-01-31 and first released in 1.29.0. The attack requires Mailpit running in its default configuration, because the advisory states that with --ui-auth-file set the percent-encoded path returns 401 rather than a 101 upgrade.
  • Why it matters: Mailpit holds exactly the mail a developer machine is not supposed to send, including password reset tokens, and on an affected version run without --ui-auth-file any page the developer visits can read it live.

send feedback on this story