cvedb.io
CVE-2024-49393
MEDIUM · CVSS 6.5
EPSS exploitation probability: 0%
Published 2024-11-12T02:15:18.443 · Last modified 2026-06-26T02:16:50.577

Summary

In neomutt and mutt, the To and Cc email headers are not validated by cryptographic signing which allows an attacker that intercepts a message to change their value and include himself as a one of the recipients to compromise message confidentiality.

Affected products

mutt — mutt

Does this affect you?

Add your gear to cvedb and we'll alert you only when mutt ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.