CVE Vulnerabilities

CVE-2026-2469

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

Published: Feb 14, 2026 | Modified: Feb 14, 2026
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Versions of the package directorytree/imapengine before 1.22.3 are vulnerable to Improper Neutralization of Special Elements in Output Used by a Downstream Component (Injection) via the id() function in ImapConnection.php due to improperly escaping user input before including it in IMAP ID commands. This allows attackers to read or delete victims emails, terminate the victims session or execute any valid IMAP command on victims mailbox by including quote characters or CRLF sequences rn in the input.

Weakness

The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.

Potential Mitigations

References