CPANSA-Email-Sender-2026-93012: Email-Sender vulnerability
| Publisher | giterlizzi | Document category | csaf_security_advisory |
|---|---|---|---|
| Initial release date | 2026-09-21T00:00:00 | Engine | CSAF Perl Toolkit 0.26 |
| Current release date | 2026-09-21T00:00:00 | Build Date | |
| Current version | 1 | Status | final |
| CVSS v3.1 Base Score | 9.8 | Severity | Critical |
| Original language | Language | en | |
| Also referred to | |||
Vulnerability Description
Email::Sender::Transport::Sendmail versions before 2.602 for Perl allow arbitrary command execution on Windows sending a message whose envelope address reaches the shell in _sendmail_pipe.
On MSWin32 the envelope sender and every recipient go into a single command string, which open() passes to a shell. Every other platform gets the list form, which runs sendmail directly. When the caller supplies no envelope, Email::Sender::Simple takes the recipients from the To and Cc headers and the sender from the From header.
An attacker who controls one of those header addresses runs commands as the sending process.
Vulnerabilities
CVE-2026-93012
Vulnerability DescriptionEmail::Sender::Transport::Sendmail versions before 2.602 for Perl allow arbitrary command execution on Windows sending a message whose envelope address reaches the shell in _sendmail_pipe.
On MSWin32 the envelope sender and every recipient go into a single command string, which open() passes to a shell. Every other platform gets the list form, which runs sendmail directly. When the caller supplies no envelope, Email::Sender::Simple takes the recipients from the To and Cc headers and the sender from the From header.
An attacker who controls one of those header addresses runs commands as the sending process.
| Weakness | CWE-78 : Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') |
|---|
Product status
Known affected
| Product | Score | ||||||||
|---|---|---|---|---|---|---|---|---|---|
| Email-Sender less than 2.602 |
|
Fixed
- Email-Sender greater than or equal 2.602
giterlizzi
Namespace: https://github.com/giterlizzi/
gdt@cpan.org
References
- CPANSA-Email-Sender-2026-93012 JSON self
https://raw.githubusercontent.com/giterlizzi/perl-CPANSA-CSAF/develop/csaf/white/2026/cpansa-email-sender-2026-93012.json - https://github.com/rjbs/Email-Sender/commit/9a587bc9ff4edae13239190c2651da2c76b1e72c.patch external
https://github.com/rjbs/Email-Sender/commit/9a587bc9ff4edae13239190c2651da2c76b1e72c.patch - https://metacpan.org/release/RJBS/Email-Sender-2.602/changes external
https://metacpan.org/release/RJBS/Email-Sender-2.602/changes - http://www.openwall.com/lists/oss-security/2026/09/21/8 external
http://www.openwall.com/lists/oss-security/2026/09/21/8 - CVE-2026-93012 (NVD) external
https://nvd.nist.gov/vuln/detail/CVE-2026-93012
Revision history
| Version | Date of the revision | Summary of the revision |
|---|---|---|
| 1 | Mon Sep 21 00:00:00 2026 | First release |
Sharing rules
TLP:WHITE
For the TLP version see: https://www.first.org/tlp/