Intel

AIKIDO-2026-10167

directorytree/imapengine is vulnerable to Command injection

Command injection Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.

73

High Risk

This Affects:

PHPdirectorytree/imapengine
1.0.0 - 1.22.2
Fixed in 1.22.3

TL;DR

Affected versions of this package are vulnerable to command injection in the IMAP ID command. User-supplied values are inserted into the command without proper escaping, allowing specially crafted input to break out of the expected format and inject additional IMAP commands.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

directorytree/imapengine is vulnerable to Command injection in versions 1.0.0 - 1.22.2.

How to fix this

Upgrade the directorytree/imapengine library to the patch version.

Background Info