Intel

AIKIDO-2025-10897

mbox-to-json is vulnerable to Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Dec 9, 2025

60

Medium Risk

This Affects:

PYTHONmbox-to-json
1.0.0 - 1.0.5
Fixed in 2.0.0
Are you affected? Scan for Free

TL;DR

Affected versions of this package are vulnerable to Command Injection via Unsafe Subprocess Execution where the attachment extraction feature directly concatenates user-controlled filenames into a shell command without sanitization, enabling attackers to exploit this by crafting malicious filenames containing shell metacharacters (e.g., semicolons or backticks) to execute arbitrary commands on the system, potentially leading to unauthorized access, data theft, or full compromise.

Who does this affect?

You are affected if you are using a vulnerable version of the package.

Background info

mbox-to-json is vulnerable to Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in versions 1.0.0 - 1.0.5.

How to fix this

Upgrade the mbox-to-json library to the patch version.