A flaw was found in mbsync before v1.3.5 and v1.4.1. mbsync doesn't validate the mailbox names returned by IMAP LIST/LSUB, which allows a malicious/compromised server to use specially crafted mailbox names containing '..' path components to access data outside the designated mailbox on the opposite end of the synchronization channel.