Email-derived URL path injection in the Swoosh Microsoft Graph adapter
Published Jul 6, 2026
2.1
LOWCVSS 4.0
EPSS 0.20%
Description
URL path injection in the Microsoft Graph adapter of Swoosh. Swoosh.Adapters.MsGraph builds its Microsoft Graph API request URL by interpolating the sender's email address into the URL path (/users/{from}/sendMail) without percent-encoding or validation.
In applications that derive the from address from untrusted or user-influenced input (for example a relay, a contact form, or a "send as" feature), an attacker can place URL-special characters such as /, ?, or # in the local part of the address to escape the intended path segment and rewrite the path and query string of the request. Because the same authenticated POST is sent with the application's Microsoft Graph bearer token, the attacker can redirect it to other Graph endpoints within the token's scopes and control the request's query string. Applications that always use a fixed, trusted from address are not affected.
This issue affects swoosh: from 1.12.0 before 1.26.3.
Affected products
-
- Version 1.12.0StatusaffectedConstraints<1.26.3
- Version
-
- Version StatusaffectedConstraints
- Version
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
Validate or reject sender addresses that contain characters outside the allowed RFC 5321 set (in particular /, ?, #, and ..) before passing the email to the adapter. Alternatively, set a static :url in the adapter configuration, which bypasses interpolation of the from address into the request path.
References (6)
- https://cna.erlef.org/cves/CVE-2026-54893.html related
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-41876 Advisory
- https://github.com/swoosh/swoosh/commit/23bfcdab71aee4613858ba6d116bb3311b72aa58 related
- https://github.com/swoosh/swoosh/commit/e38235453e81d1727bfc8d91e69ec4cb211ccf61 patch
- https://github.com/swoosh/swoosh/security/advisories/GHSA-754j-98wh-57rf vendor-advisoryrelated
- https://osv.dev/vulnerability/EEF-CVE-2026-54893 related
Change history (0)
No recorded changes yet.