CRITICAL 9.8 npm
YouTransfer has an issue in the sendmail transport integration that allows arbitrary code execution
GHSA-68mc-h6h8-79wj · CVE-2026-50880
Published · Modified
AI SAST
Find this class of vulnerability in your own code
Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.
Description
An issue in the sendmail transport integration component of YouTransfer v1.0.6 allows attackers to execute arbitrary code via supplying a crafted request.
Ready to move
Start Securing
Free, no credit card | First findings in minutes