CVE-2026-81730: Dolibarr 9.0.0 through 23.0.4 Path Traversal via EmailCollector Attachment Filename
Dolibarr 9.0.0 through 23.0.4 saves inbound email attachments under the name supplied in the message's MIME headers without reducing it to a safe basename. The global saveAttachment() in htdocs/emailcollector/lib/emailcollector.lib.php builds $filepath = $path . $filename . '.' . $ext and hands it to fileputcontents(), and the private saveAttachment() in htdocs/emailcollector/class/emailcollector.class.php writes to $destdir.'/'.$filename; the name reaches both from the attachment's own getName() or getFilename() value by way of the record-join, create-ticket and create-project operations. A traversal sequence in the filename therefore survives intact, so any sender who can email a mailbox that an EmailCollector monitors, which is the module's ordinary use for a support or ticket inbox, can place attacker-controlled content outside the per-object attachment directory without holding a Dolibarr account. Under the hardened layout Dolibarr's SECURITY.md requires, with htdocs read-only, the write is confined to the documents tree and corrupts or forges other objects' documents; where htdocs is writable the same primitive reaches a web-executable path. Version 24.0.0 applies dolsanitizePathName() and dolsanitizeFileName() before the write.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Dolibarr EmailCollectorto a version that resolves this vulnerability.Fixed in 24.0.0 - Configuration
Apply the Dolibarr SECURITY.md hardened layout requirement that htdocs is read-only, so the EmailCollector attachment write is confined to the documents tree rather than corrupting/forging other objects or reaching a web-executable path.
Dolibarr SECURITY.md hardened layout (htdocs read-only) = htdocs read-only
Event History
Frequently Asked Questions
Who can exploit this issue?
Any sender able to email a mailbox monitored by Dolibarr's EmailCollector can exploit it. The attacker does not need a Dolibarr account, and support or ticket inboxes are an ordinary affected use case.
What configurations face the greatest impact?
In Dolibarr's hardened layout, where htdocs is read-only, writes are confined to the documents tree but can still corrupt or forge documents belonging to other objects. If htdocs is writable, attacker-controlled content can be written to a web-executable path.
Which attachment-processing operations are affected?
The vulnerable filename handling is reached through record-join, create-ticket, and create-project operations. Attachment names obtained from MIME getName() or getFilename() values can contain traversal sequences.
What version contains the remediation?
Version 24.0.0 applies dol_sanit…