Dovecot has provided a script to use for attachment to text conversion. This script unsafely handles zip-style attachments. Attacker can use specially crafted OOXML documents to cause unintended files on the system to be indexed and subsequently ending up in FTS indexes. Do not use the provided script, instead, use something else like FTS tika. No publicly available exploits are known.
Metrics
Affected Vendors & Products
References
History
Fri, 27 Mar 2026 10:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Unsafe Attachment Conversion Script Allows Unauthorized File Indexing via Crafted OOXML |
Fri, 27 Mar 2026 08:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Dovecot has provided a script to use for attachment to text conversion. This script unsafely handles zip-style attachments. Attacker can use specially crafted OOXML documents to cause unintended files on the system to be indexed and subsequently ending up in FTS indexes. Do not use the provided script, instead, use something else like FTS tika. No publicly available exploits are known. | |
| Weaknesses | CWE-200 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: OX
Published:
Updated: 2026-03-27T19:42:40.634Z
Reserved: 2025-09-08T14:22:28.105Z
Link: CVE-2025-59031
No data.
Status : Received
Published: 2026-03-27T09:16:18.783
Modified: 2026-03-27T09:16:18.783
Link: CVE-2025-59031
No data.
OpenCVE Enrichment
Updated: 2026-03-27T09:45:47Z