You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
Bypass of email address domain restrictions
High
erinosher
published
GHSA-3g4h-9h37-mpx6May 26, 2026
Package
forem
(forem)
Affected versions
All versions before commit a2ab6d4
Patched versions
All versions from commit a2ab6d4
Description
Impact
A maliciously crafted email address could allow an attacker to bypass domain allowlist or denylist restrictions and gain access to invite-only forem deployments.
Impact
A maliciously crafted email address could allow an attacker to bypass domain allowlist or denylist restrictions and gain access to invite-only forem deployments.
Patches
The issue is patched as of a2ab6d4
Workarounds
Some SMTP servers and email delivery providers may drop or refuse to send maliciously crafted email addresses.