๐Ÿ” CVE Alert

CVE-2026-48780

HIGH 8.2

Forem vulnerable to bypass of email address domain restrictions

CVSS Score
8.2
EPSS Score
0.0%
EPSS Percentile
0th

Forem is open source software for building communities. Prior to commit a2ab6d4, a maliciously crafted email address could allow an attacker to bypass domain allowlist or denylist restrictions and gain access to invite-only forem deployments. The issue is patched as of `a2ab6d4`. As a workaround, some SMTP servers and email delivery providers may drop or refuse to send maliciously crafted email addresses.

CWE CWE-287
Vendor forem
Product forem
Published Jun 16, 2026
Stay Ahead of the Next One

Get instant alerts for forem forem

Be the first to know when new high vulnerabilities affecting forem forem are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
Low
Availability
None

Affected Versions

forem / forem
< a2ab6d4

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/forem/forem/security/advisories/GHSA-3g4h-9h37-mpx6 github.com: https://github.com/forem/forem/commit/a2ab6d409d2676eb0711ecbd737192043125b437