Skip to content

cypht

v2.11.1 Security

This release includes 1 security fix for security teams reviewing exposed deployments.

Published 17d Communication & Email
✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 1 known CVE

Topics

atom e-mail ews imap jmap news-reader
+6 more
php pop3 rss smtp webmail webmail-client

ReleasePort's take

Moderate signal
editorial:auto 11d

Version v2.11.1 improves MSTNEF attachment parsing safety and temp file handling in module/imap.

Why it matters: Addresses a security issue (severity 70) affecting the imap module; upgrade to v2.11.1 if using this surface.

Summary

AI summary

Improved MSTNEF attachment parsing safety and temp file handling.

Changes in this release

Security High

Improves MSTNEF attachment parsing safety and temp file handling in module/imap.

Improves MSTNEF attachment parsing safety and temp file handling in module/imap.

Source: llm_adapter@2026-07-16

Confidence: high

Full changelog

Security fixes only

  • fix(module/imap): improve MSTNEF attachment parsing safety and temp file handling by @mercihabam in #2027

We greatly appreciate Ki1ro for identifying and reporting the security concerns addressed in this release. Thank you for your collaboration and commitment!

Full Changelog: https://github.com/cypht-org/cypht/compare/v2.11.0...v2.11.1

Security Fixes

  • Security improvement in module/imap: safer MSTNEF attachment parsing and temp file handling (reported by Ki1ro).

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track cypht

Get notified when new releases ship.

Sign up free

About cypht

Cypht: Lightweight Open Source webmail aggregator [PHP, JS]. Supports IMAP/SMTP, JMAP and EWS (Exchange Web Services)

All releases →

Related context

Related tools

Beta — feedback welcome: [email protected]