A vulnerability classified as critical has been found in ruby net-imap up to 0.4.23/0.5.13/0.6.3. Affected by this issue is the function
Net::IMAP. This manipulation causes command injection.
This vulnerability appears as CVE-2026-42258. The attack requires local access. There is no available exploit.
It is recommended to upgrade the affected component.