The MailPreview feature of debugkit is vulnerable to arbitrary constructor execution. For an application to be vulnerable the following conditions must be true:
debug mode must be enabled.5.2.4 and 4.10.3 contain patches for this issue.
Ensure that debugkit is only part of your development dependencies, and that debug mode is disabled in production environments.
{
"cwe_ids": [
"CWE-470"
],
"github_reviewed": true,
"github_reviewed_at": "2026-08-26T15:31:01Z",
"nvd_published_at": null,
"severity": "MODERATE"
}