Skip to main content

CVE-2026-93012: CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

0
Critical
VulnerabilityCVE-2026-93012cvecve-2026-93012cwe-78
Published: 09/21/2026 (09/21/2026, 17:19:27 UTC)
Source: CVE Database V5

Description

Email::Sender::Transport::Sendmail versions before 2.602 for Perl allow arbitrary command execution on Windows sending a message whose envelope address reaches the shell in _sendmail_pipe. On MSWin32 the envelope sender and every recipient go into a single command string, which open() passes to a shell. Every other platform gets the list form, which runs sendmail directly. When the caller supplies no envelope, Email::Sender::Simple takes the recipients from the To and Cc headers and the sender from the From header. An attacker who controls one of those header addresses runs commands as the sending process.

Affected software

GitHub Actionsmore threats →cve
Email-Sender
pkg:github/Email-Sender
Affected versions
>=0 <2.602

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/21/2026, 17:46:30 UTC

Technical Analysis

CVE-2026-93012 is an OS command injection vulnerability in Email::Sender::Transport::Sendmail versions prior to 2.602 on Windows platforms. The vulnerability arises because the envelope sender and recipient addresses are combined into a single command string that is passed to the shell via open(), allowing an attacker who controls these header addresses to execute arbitrary commands with the privileges of the sending process. Non-Windows platforms are not affected as they use a list form to run sendmail directly. The vulnerability is due to improper neutralization of special elements used in OS commands (CWE-78).

Potential Impact

An attacker who can control the envelope sender or recipient addresses in an email can execute arbitrary commands on the Windows system running the vulnerable Email::Sender::Transport::Sendmail module. This could lead to full compromise of the sending process's privileges. Other platforms are not affected by this issue.

Mitigation Recommendations

A fixed version 2.602 or later is available that addresses this vulnerability. Users should upgrade to Email::Sender::Transport::Sendmail version 2.602 or newer to remediate this issue. No other mitigation guidance is provided.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Data Version
5.2
Assigner Short Name
CPANSec
Date Reserved
2026-09-17T14:38:04.344Z
State
PUBLISHED

Threat ID: 6ab16a2a55bf5e2cf53d2b82

Added to database: 09/21/2026, 17:32:26 UTC

Last enriched: 09/21/2026, 17:46:30 UTC

Last updated: 09/22/2026, 01:47:10 UTC

Views: 13

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses