Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-54649— punchin-email: Operator inbox (FORWARD_TO) disclosed to correspondents on reply — Cloudflare forward() drops the relay Reply-To

Quick assessment

Affected
PunchIn-App punchin-email
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

punchin-email 是一个 Cloudflare Email Worker,提供双向角色别名(role aliases)功能,并将邮件中继转发到私有收件箱。在 1.5.0 版本之前, 函数在处理传入的别名邮件时,使用 进行转发。这一操作会静默丢弃原本用于将回复邮件经由中继转发的 头。因此,当通信方发送邮件给某个别名,而管理员进行回复时,邮件客户端可能直接从私有的 收件箱地址向通信方发送回复邮件,从而暴露该私有地址。 此问题的影响仅限于管理员自身的邮箱地址,不会泄露第三方数据,也不会导致代码执行或身份验证绕过

CVSS 2.1 · Low

Possible ATT&CK Techniques 1 AI

T1190 · Exploit Public-Facing Application

Affected Version Matrix 1

VendorProduct Version RangeStatus
PunchIn-App punchin-email < 1.5.0 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-54649

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
punchin-email: Operator inbox (FORWARD_TO) disclosed to correspondents on reply — Cloudflare forward() drops the relay Reply-To
Source: CVE Program / CVE List V5
Vulnerability Description
punchin-email is a Cloudflare Email Worker that provides two-way role aliases while relaying mail to a private inbox. Prior to 1.5.0, handleInbound delivers inbound alias mail with message.forward(), which silently drops the added Reply-To header intended to route responses through the relay. When a correspondent sends mail to an alias and the operator replies, the mail client can send directly to the correspondent from the private FORWARD_TO inbox address, exposing that address. The disclosure is limited to the operator's own email address and does not expose third-party data or provide code execution or authentication bypass. This issue is fixed in version 1.5.0.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
信息暴露
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
PunchIn-App punchin-email < 1.5.0 -

II. Public POCs for CVE-2026-54649

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-54649

登录查看更多情报信息。

Patches & Fixes for CVE-2026-54649 (2)

Vendor Advisories for CVE-2026-54649 (1)

Vendor Pages for CVE-2026-54649 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-54649

No comments yet


Leave a comment