๐Ÿ” CVE Alert

CVE-2026-54649

UNKNOWN 0.0

punchin-email: Operator inbox (FORWARD_TO) disclosed to correspondents on reply โ€” Cloudflare forward() drops the relay Reply-To

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

punchin-email is a Cloudflare Email Worker that provides two-way role aliases while relaying mail to a private inbox. Prior to 1.5.0, handleInbound delivers inbound alias mail with message.forward(), which silently drops the added Reply-To header intended to route responses through the relay. When a correspondent sends mail to an alias and the operator replies, the mail client can send directly to the correspondent from the private FORWARD_TO inbox address, exposing that address. The disclosure is limited to the operator's own email address and does not expose third-party data or provide code execution or authentication bypass. This issue is fixed in version 1.5.0.

CWE CWE-200 CWE-201
Vendor punchin-app
Product punchin-email
Published Sep 17, 2026
Stay Ahead of the Next One

Get instant alerts for punchin-app punchin-email

Be the first to know when new unknown vulnerabilities affecting punchin-app punchin-email are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

PunchIn-App / punchin-email
< 1.5.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/PunchIn-App/punchin-email/security/advisories/GHSA-2ph7-69xm-hmwv github.com: https://github.com/PunchIn-App/punchin-email/pull/66 github.com: https://github.com/PunchIn-App/punchin-email/commit/593685ffc0b8eb3949a4838e7bfe1e97b953d084 github.com: https://github.com/PunchIn-App/punchin-email/releases/tag/v1.5.0