A AegiFlow
CRITICALCVSS 9.8EPSS 0.5%

CVE-2026-50880

YouTransfer has an issue in the sendmail transport integration that allows arbitrary code execution

Published
2026-06-15
Modified
2026-08-26
EPSS percentile
39%
Aliases
GHSA-68mc-h6h8-79wj
Sources
github-advisory

Summary

An issue in the sendmail transport integration component of YouTransfer v1.0.6 allows attackers to execute arbitrary code via supplying a crafted request.

Affected packages

EcosystemPackageAffected versionsFixed versions
npmyoutransfer

Remediation: No patched version is listed by GitHub.

References

Includes data from the GitHub Advisory Database, licensed under CC-BY 4.0.

CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.

EPSS scores provided by the FIRST.org Exploit Prediction Scoring System.