FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

mail/mailpit -- Cross-Site WebSocket Hijacking

Affected packages
mailpit < 1.28.2

Details

VuXML ID d822839e-ee4f-11f0-b53e-0897988a1c07
Discovery 2026-01-10
Entry 2026-01-10

Mailpit author reports:

The Mailpit WebSocket server is configured to accept connections from any origin. This lack of Origin header validation introduces a Cross-Site WebSocket Hijacking (CSWSH) vulnerability.

An attacker can host a malicious website that, when visited by a developer running Mailpit locally, establishes a WebSocket connection to the victim's Mailpit instance (default ws://localhost:8025). This allows the attacker to intercept sensitive data such as email contents, headers, and server statistics in real-time.

References

CVE Name CVE-2026-22689
URL https://github.com/axllent/mailpit/security/advisories/GHSA-524m-q5m7-79mm