apple-mail
Audited by Socket on Sep 25, 2026
4 alerts found:
SecurityAnomalyx3This is a mail-reply utility with a consequential AppleScript injection weakness: untrusted arguments are interpolated into executable AppleScript with incomplete escaping. An attacker able to control its arguments could potentially alter the script and cause unintended Mail actions. The sending behavior itself matches the stated purpose; the fragment does not otherwise show clear malware behavior.
The script performs the stated task of deleting Mail messages, but it builds SQL, Python, and AppleScript source using unescaped external or database-derived values. This creates injection risks, especially if arguments or Mail database contents are attacker-controlled. No clear evidence of malware or data exfiltration appears in the code.
No overt malicious payload behavior (no networking, persistence, or system modification) is evident. However, the script has meaningful security/privacy risks: it outputs full email bodies to stdout (high privacy impact) and it uses unsafe dynamic interpolation of an unvalidated, user-controlled MSG_ID into a sqlite3 SQL statement and an AppleScript heredoc (injection/logic manipulation risk). Use should be restricted to trusted local inputs, with the message content treated as highly sensitive and not logged or shared.
No direct indicators of hidden malware (e.g., obfuscation, backdoors, or credential/data theft) are present. However, the script executes AppleScript and performs a real ‘send email’ action, while embedding multiple untrusted inputs directly into AppleScript code with only partial escaping (double quotes in SUBJECT/BODY only) and with no sanitization for TO/FROM_ACCOUNT/ATTACHMENT. This creates a meaningful security risk of AppleScript/template manipulation and/or unwanted email sending and arbitrary file attachment when inputs are not fully trusted.