GHSA-68mc-h6h8-79wj

Suggest an improvement
Source
https://github.com/advisories/GHSA-68mc-h6h8-79wj
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-68mc-h6h8-79wj/GHSA-68mc-h6h8-79wj.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-68mc-h6h8-79wj
Aliases
  • CVE-2026-50880
Published
2026-06-15T21:30:41Z
Modified
2026-08-26T15:26:24Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
YouTransfer has an issue in the sendmail transport integration that allows arbitrary code execution
Details

An issue in the sendmail transport integration component of YouTransfer v1.0.6 allows attackers to execute arbitrary code via supplying a crafted request.

Database specific
{
    "cwe_ids":  [
        "CWE-94"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-08-26T15:04:18Z",
    "nvd_published_at":  "2026-06-15T20:16:30Z",
    "severity":  "CRITICAL"
}
References

Affected packages

npm / youtransfer

Package

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Last Affected
1.0.6

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-68mc-h6h8-79wj/GHSA-68mc-h6h8-79wj.json"