Intel

AIKIDO-2026-10167

directorytree/imapengine is vulnerable to Command injection

Command injection Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Feb 12, 2026

73

High Risk

This Affects:

PHPdirectorytree/imapengine
1.0.0 - 1.22.2
Fixed in 1.22.3
Are you affected? Scan for Free

TL;DR

Affected versions of this package are vulnerable to command injection in the IMAP ID command. User-supplied values are inserted into the command without proper escaping, allowing specially crafted input to break out of the expected format and inject additional IMAP commands.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

directorytree/imapengine is vulnerable to Command injection in versions 1.0.0 - 1.22.2.

How to fix this

Upgrade the directorytree/imapengine library to the patch version.