GHSA-389r-rccm-h3h5

Suggest an improvement
Source
https://github.com/advisories/GHSA-389r-rccm-h3h5
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/03/GHSA-389r-rccm-h3h5/GHSA-389r-rccm-h3h5.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-389r-rccm-h3h5
Aliases
Published
2026-03-05T00:16:57Z
Modified
2026-07-13T07:26:20Z
Severity
  • 5.5 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N CVSS Calculator
Summary
eml_parser: Path Traversal in Official Example Script Leads to Arbitrary File Write
Details

Summary

The official example script examples/recursively_extract_attachments.py contains a path traversal vulnerability that allows arbitrary file write outside the intended output directory. Attachment filenames extracted from parsed emails are directly used to construct output file paths without any sanitization, allowing an attacker-controlled filename to escape the target directory.

Details

File: examples/recursively_extract_attachments.py Lines: 61–64

for a in m['attachment']:
    out_filepath = out_path / a['filename']  # No sanitization
    print(f'\tWriting attachment: {out_filepath}')
    with out_filepath.open('wb') as a_out:
        a_out.write(base64.b64decode(a['raw']))

The value a['filename'] is attacker-controlled via crafted email attachment headers:

Content-Disposition: attachment; filename="../outside/pwned.txt"

No path normalization or boundary validation is performed before writing.

PoC

  1. Create a malicious .eml file:
Content-Disposition: attachment; filename="../outside/pwned.txt"
  1. Run the example script:
python recursively_extract_attachments.py -p ./emails -o ./safe
  1. Expected: ./safe/pwned.txt
  2. Actual: ./outside/pwned.txt ← written outside the intended directory

Verified on Kali Linux with eml_parser installed via pip in a virtual environment.

Impact

This vulnerability is limited to the example script only and does not affect the core eml_parser library. However, as the script is part of the official repository and is likely to be adapted for production use, an attacker supplying a crafted email could achieve arbitrary file write within the execution context.

Potential attack scenarios include:

  • Cron job injection: filename="../../etc/cron.d/backdoor"
  • Web shell upload: filename="../../var/www/html/shell.php"
  • SSH key injection: filename="../../home/user/.ssh/authorized_keys"

Recommended Fix

import os.path

for a in m['attachment']:
    filename = os.path.basename(a['filename'])
    out_filepath = out_path / filename

    if not out_filepath.resolve().is_relative_to(out_path.resolve()):
        print(f'[!] Skipping suspicious filename: {a["filename"]}')
        continue

    print(f'\tWriting attachment: {out_filepath}')
    with out_filepath.open('wb') as a_out:
        a_out.write(base64.b64decode(a['raw']))
Database specific
{
    "cwe_ids":  [
        "CWE-22"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-03-05T00:16:57Z",
    "nvd_published_at":  "2026-03-07T16:15:55Z",
    "severity":  "MODERATE"
}
References

Affected packages

PyPI / eml-parser

Package

Name
eml-parser
View open source insights on deps.dev
Purl
pkg:pypi/eml-parser

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2.0.1

Affected versions

0.*
0.9
1.*
1.0
1.1
1.3
1.4
1.5
1.6
1.7
1.8
1.9
1.10
1.11
1.11.1
1.11.2
1.11.4
1.11.5
1.11.6
1.11.7
1.12.0
1.13.0
1.14.0
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.14.7
1.14.8
1.15.0
1.16.0
1.17.0
1.17.1
1.17.2
1.17.3
1.17.4
1.17.5
2.*
2.0.0

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/03/GHSA-389r-rccm-h3h5/GHSA-389r-rccm-h3h5.json"