CVE-2026-58451
MEDIUMHorde IMP < 7.0.1 Path Traversal via Compose.php img src
Title source: cnaDescription
Horde IMP before 7.0.1 contains a path traversal vulnerability in lib/Compose.php that allows authenticated attackers to read arbitrary files from the server filesystem by embedding traversal sequences after a CKEditor path prefix in img src URLs. Attackers can bypass the stripos() prefix validation by appending sequences such as traversal segments after the matching prefix, causing file_get_contents() to read sensitive files whose contents are then exfiltrated as MIME parts in outgoing email; unauthenticated exploitation is also achievable via CSRF against an active authenticated session.
References (7)
Core 7
Core References
Third Party Advisory third-party-advisory
https://www.vulncheck.com/advisories/horde-imp-path-traversal-via-compose-php-img-src
Exploit technical-description
exploit
Researcher Disclosure
https://blog.evan.lat/posts/CVE-2026-58451/
Mailing List
http://seclists.org/fulldisclosure/2026/Jul/8
Scores
CVSS v3
6.5
EPSS
0.0041
EPSS Percentile
33.6%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-22
Status
published
Products (1)
horde/imp
< 7.0.1
Published
Jul 01, 2026
Tracked Since
Jul 02, 2026