CVEReports
CVEReports

Automated vulnerability intelligence platform. Comprehensive reports for high-severity CVEs generated by AI.

Product

  • Home
  • Sitemap
  • RSS Feed

Company

  • About
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CVEReports. All rights reserved.

Made with love by Amit Schendel & Alon Barad



CVE-2026-2469

Return to Sender: Unauthenticated IMAP Command Injection in directorytree/imapengine

Alon Barad
Alon Barad
Software Engineer

Feb 17, 2026·6 min read·43 visits

Executive Summary (TL;DR)

The `id()` method in `directorytree/imapengine` (< 1.22.3) concatenates user input directly into IMAP commands without escaping. Attackers can inject double quotes and CRLF sequences to execute unauthorized commands like `FETCH` or `LOGOUT`.

A critical failure in input sanitization within the `directorytree/imapengine` PHP library allows attackers to perform IMAP Command Injection. By manipulating the parameters passed to the `id()` method, malicious actors can break out of the protocol's quoted-string syntax and inject arbitrary IMAP commands. This can lead to unauthorized email exfiltration, data modification, or denial of service against the mail server.

The Protocol That Time Forgot

IMAP (Internet Message Access Protocol) is one of those ancient, text-based protocols that holds the internet together with duct tape and hope. Unlike modern binary protocols that clearly delineate data from instructions, IMAP relies heavily on line-based ASCII commands. If you've ever telnetted into port 143, you know the drill: you type a tag, a command, and arguments. The server responds. It's chatty, it's human-readable, and it is absolutely terrifying if you mishandle user input.

Enter directorytree/imapengine, a PHP library designed to abstract away the pain of raw socket handling. It promises a clean, object-oriented interface for developers who don't want to manually parse RFC 3501. Ideally, a wrapper library acts as a bodyguard, sanitizing inputs and ensuring that when a developer asks to "identify the client," the library doesn't accidentally tell the server to "delete all emails."

Unfortunately, in version 1.22.3 and below, imapengine forgot its primary job. It treated the IMAP ID extension (RFC 2971)—used to tell the server things like "I am an iPhone" or "I am Outlook"—as a trusted zone. By failing to sanitize the inputs destined for this command, the library opened a direct pipe for attackers to speak raw IMAP to the backend server, bypassing the application's intended logic entirely.

The Flaw: Concatenation implies Trust

The vulnerability lies in how imapengine constructs the ID command. The IMAP ID command allows a client to send a list of field-value pairs to the server for identification purposes. The RFC expects these values to be 'quoted-strings'. For example, a legitimate command might look like this:

A001 ID ("name" "MyEmailApp" "version" "1.0")

The flaw is a textbook Injection vulnerability (CWE-74). The library takes an array of parameters provided by the developer (which may originate from user input, like a 'Client Name' setting in a webmail app) and naively concatenates them into the command string. It wraps them in double quotes, assuming that the input itself won't contain double quotes.

This is the coding equivalent of locking your front door but leaving the key under the mat with a neon sign pointing to it. Because the library didn't check for the presence of " characters or CRLF (Carriage Return Line Feed) sequences inside the input, an attacker can simply close the quote, add a space, and start typing their own IMAP commands. The server, being a dutiful line-processing machine, executes them without hesitation.

The Smoking Gun

Let's look at the code. The vulnerability exists in src/Connection/ImapConnection.php within the id() method. Here is the vulnerable logic prior to the patch:

// VULNERABLE CODE
public function id(?array $ids = null): UntaggedResponse
{
    // ... setup code ...
    $token = '(';
 
    foreach ($ids as $id) {
        // CRITICAL FLAW: No escaping of $id
        $token .= '"'.$id.'" ';
    }
 
    $token = rtrim($token).')';
    
    // Sends: TAG ID ("value1" "value2")
    return $this->command('ID', $token);
}

See that $token .= '"'.$id.'" '; line? That is where the world ends. If $id contains ", the structure of the IMAP command breaks. If $id contains \r\n, the command terminates, and a new command begins.

Here is how the maintainers fixed it in version 1.22.3. They introduced a sanitization helper (likely Str::escape or similar logic) to handle the dirty work:

// PATCHED CODE
foreach ($ids as $id) {
    // FIX: Input is escaped before concatenation
    $token .= '"'.Str::escape($id).'" ';
}

The fix is boring, which is exactly how security patches should be. It escapes quotes and presumably strips or encodes control characters, ensuring the data remains data and never becomes code.

The Exploit: Break, Enter, Execute

Exploiting this requires controlling a string passed to the id() method. Let's assume the application allows us to set a custom "Device Name" that gets logged via IMAP.

Step 1: The Breakout If we send the string MyDevice, the library sends: ... ("name" "MyDevice"). If we send My"Device, the library sends: ... ("name" "My"Device"). This is a syntax error in IMAP, but we want execution, not errors.

Step 2: The Injection We need to terminate the current command and start a new one. IMAP commands are separated by CRLF (\r\n). Our payload needs to:

  1. Close the current quote: "
  2. Inject the CRLF: \r\n
  3. Write a valid IMAP tag and command: A666 LOGOUT
  4. Clean up the trailing garbage the library appends: \r\nTAG_IGN ID ("

The Payload: evil"\r\nA666 LOGOUT\r\nA002 ID ("ign

The Resulting Stream:

A001 ID ("name" "evil"
A666 LOGOUT
A002 ID ("ign")

The server sees three distinct lines. It processes the first (likely fails or ignores the partial ID). Then it hits A666 LOGOUT. The server immediately terminates the authenticated session. Boom, Denial of Service.

But we can do better. If we are authenticated (or if this runs post-auth), we can inject: evil"\r\nA666 FETCH 1:* (BODY[])\r\nA002 ID ("ign

This commands the server to dump the entire inbox content to the socket. The application might crash processing the unexpected response, but an attacker capturing network traffic (or if the app reflects the raw response) just stole the user's mail.

Impact Assessment

Why should you panic? Because IMAP is the gateway to the kingdom. If an attacker can inject commands here, the impact ranges from annoying to catastrophic depending on the application's implementation.

  1. Confidentiality Loss (High): As demonstrated, injecting FETCH commands allows retrieving email headers, bodies, and attachments. In a password reset scenario, this means account takeover.
  2. Integrity Loss (Medium): Attackers can inject STORE commands to modify flags (e.g., marking unread emails as read to hide activity) or EXPUNGE to permanently delete messages.
  3. Availability Loss (High): The LOGOUT injection is a trivial way to kill sessions repeatedly, rendering the mail service unusable for the target.

This vulnerability is particularly dangerous because it often occurs in background workers or "setup" phases where detailed logging (via the ID command) is common.

Mitigation Strategy

The remediation is straightforward, but urgency is required.

1. Patch Immediately Update directorytree/imapengine to version 1.22.3 or higher. This version includes the necessary escaping logic in the id() method.

2. Defensive Coding Even with the patch, never trust user input destined for protocol wrappers. Validate configuration inputs (like client names or device IDs) against a strict allowlist (e.g., alphanumeric only). There is rarely a valid reason for a device name to contain a carriage return.

3. Network Monitoring Configure your IDS/IPS (Snort/Suricata) to look for anomalies in IMAP traffic, specifically client-to-server packets containing multiple distinct commands in a single TCP PSH frame where the application logic dictates only one should be sent.

Official Patches

DirectoryTreePull Request #150: Fix ID command injection

Fix Analysis (1)

Technical Appendix

CVSS Score
7.6/ 10
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H
EPSS Probability
0.01%
Top 97% most exploited

Affected Systems

PHP applications using directorytree/imapengine < 1.22.3Webmail clientsEmail processing workers

Affected Versions Detail

Product
Affected Versions
Fixed Version
directorytree/imapengine
DirectoryTree
< 1.22.31.22.3
AttributeDetail
CWE IDCWE-74 / CWE-93
Attack VectorNetwork (IMAP Protocol)
CVSS v3.17.6 (High)
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H
Exploit StatusProof of Concept Available
PlatformPHP

MITRE ATT&CK Mapping

T1059Command and Scripting Interpreter
Execution
T1114Email Collection
Collection
T1071.003Application Layer Protocol: Mail Protocols
Command and Control
CWE-74
Injection

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

Known Exploits & Detection

GistProof of Concept for CVE-2026-2469 showing session termination

Vulnerability Timeline

Patch Committed (PR #150)
2026-02-03
PoC Published
2026-02-04
CVE-2026-2469 Published
2026-02-14

References & Sources

  • [1]Snyk Advisory
  • [2]RFC 2971 - IMAP ID Extension

Attack Flow Diagram

Press enter or space to select a node. You can then use the arrow keys to move the node around. Press delete to remove it and escape to cancel.
Press enter or space to select an edge. You can then press delete to remove it or escape to cancel.

More Reports

•10 minutes ago•CVE-2026-61427
7.3

CVE-2026-61427: Authentication Bypass and Unvalidated Tool Execution in PraisonAI MCP HTTP-Stream Server

CVE-2026-61427 is a critical authentication bypass and improper input validation vulnerability within the Model Context Protocol (MCP) HTTP-stream server of PraisonAI. In versions prior to 4.6.78, the server lacks authentication by default and forwards client messages directly to Python tool handlers without input validation. When bound to non-localhost interfaces, this permits unauthenticated remote attackers to perform unauthorized administrative operations and execute tools.

Alon Barad
Alon Barad
0 views•4 min read
•about 1 hour ago•CVE-2026-107387
6.2

CVE-2026-107387: Uncontrolled Memory Allocation (OOM) in music-metadata APEv2 Parser

CVE-2026-107387 is a high-impact uncontrolled memory allocation vulnerability in music-metadata, a widely used Node.js metadata parser. The flaw occurs in the APEv2 tag parser, where the library reads an attacker-controlled 32-bit integer indicating the tag size and immediately requests a corresponding heap buffer reservation. Because this allocation occurs before validating if the input stream actually contains those bytes, an attacker can supply a minuscule audio file to trigger large, disproportionate allocations, resulting in heap exhaustion and an uncatchable process-wide Out of Memory (OOM) crash.

Amit Schendel
Amit Schendel
3 views•5 min read
•about 2 hours ago•CVE-2026-107391
6.2

CVE-2026-107391: Synchronous Infinite Loop and Memory Exhaustion in music-metadata MP4 Parser

An input validation vulnerability exists in music-metadata versions prior to 11.16.0, where parsing a crafted MP4 file containing a sample-description (stsd) box with a zero-value size entry causes a synchronous infinite loop and memory exhaustion, resulting in complete Denial of Service.

Alon Barad
Alon Barad
6 views•7 min read
•about 3 hours ago•CVE-2026-107377
7.5

CVE-2026-107377: Arbitrary File Write and Overwrite via Protobuf Weak Import Path Traversal in datamodel-code-generator

A path traversal vulnerability in datamodel-code-generator allows remote attackers to write or overwrite arbitrary files on the local host filesystem via a manipulated Protobuf schema containing malicious weak import paths.

Amit Schendel
Amit Schendel
9 views•5 min read
•about 4 hours ago•CVE-2026-61431
6.8

CVE-2026-61431: Arbitrary Local File Read and Path Traversal in PraisonAI ContextGatherer

PraisonAI is vulnerable to an arbitrary local file read vulnerability prior to version 4.6.78. The flaw is in the ContextGatherer component, where validation checks are executed only after files are parsed and appended to the context bundle, bypassing security constraints.

Amit Schendel
Amit Schendel
8 views•6 min read
•about 5 hours ago•CVE-2026-107212
7.5

CVE-2026-107212: CPU Exhaustion Denial of Service via Look-Ahead Row Parsing in Excelize

An algorithmic complexity vulnerability (CWE-770) in the Excelize library allows remote attackers to cause resource exhaustion (100% CPU usage) via a crafted Microsoft Excel spreadsheet. This occurs because the look-ahead row index parsing in Rows.Columns() fails to enforce upper boundary limits, enabling an out-of-bounds row index to trigger an infinite seek loop inside the Rows iterator.

Alon Barad
Alon Barad
14 views•6 min read