mirror of
https://github.com/axllent/mailpit.git
synced 2025-05-19 22:23:25 +02:00
This closes a security hole whereby a bad actor with SMTP access can bypass the CSP headers with a series of specially crafted HTML messages. A special thanks to @bmodotdev for responsibly disclosing the vulnerability and proving information and an initial fix.