Impact
The flaw disables authentication checks on the SES.sendEmail Lambda function’s email parameters—recipient addresses, cc, reply‑to, subject, and message—allowing unauthenticated users to invoke the endpoint and send arbitrary emails. The resulting impact is moderate, reflected by a CVSS score of 6.9, and could enable phishing, spam, or other malicious email campaigns by an attacker.
Affected Systems
The vulnerable component is simalexan’s api‑lambda‑send‑email‑ses. It follows a rolling‑release model and specific affected commit ranges are not published, so any active deployment may be susceptible until a fix is released.
Risk and Exploitability
The vulnerability is exploitable remotely through the API Gateway endpoint; no authentication is required to invoke the function. The CVSS score of 6.9 indicates less than 1 % suggests a low likelihood of widespread exploitation, and the issue is not listed in the CISA KEV catalog. An attacker with network access to the Gateway could send arbitrary emails to any address, potentially compromising confidentiality, integrity, or availability of the email system.
OpenCVE Enrichment