CVE-2024-27448
MailDev Remote Code Execution
9.8
CRITICAL
CVSS 3.1
EPSS 13.0%
Description
MailDev 2 through 2.1.0 allows Remote Code Execution via a crafted Content-ID header for an e-mail attachment, leading to `lib/mailserver.js` writing arbitrary code into the `routes.js` file.
How to fix CVE-2024-27448
No fixed version has been published yet. Mitigate by removing the affected package or applying upstream guidance from the references below.
- npm/maildev—no fix listed
Is CVE-2024-27448 being exploited?
Moderate — EPSS is 13.0%. Track this CVE but it's not at the top of the prioritisation list.
Affected packages (1)
- >= 2.0.0-beta1, <= 2.1.0
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | CRITICAL9.8 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |