Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-7gmj-h9xc-mcxc | mailparser vulnerable to Cross-site Scripting |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Wed, 04 Mar 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Nodemailer
Nodemailer mailparser |
|
| Vendors & Products |
Nodemailer
Nodemailer mailparser |
Tue, 03 Mar 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 03 Mar 2026 05:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Versions of the package mailparser before 3.9.3 are vulnerable to Cross-site Scripting (XSS) via the textToHtml() function due to the improper sanitisation of URLs in the email content. An attacker can execute arbitrary scripts in victim browsers by adding extra quote " to the URL with embedded malicious JavaScript code. | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: snyk
Published:
Updated: 2026-03-03T15:17:56.714Z
Reserved: 2026-03-02T18:41:43.509Z
Link: CVE-2026-3455
Updated: 2026-03-03T15:11:40.011Z
Status : Awaiting Analysis
Published: 2026-03-03T05:17:25.240
Modified: 2026-03-03T21:52:29.877
Link: CVE-2026-3455
No data.
OpenCVE Enrichment
Updated: 2026-03-04T21:04:06Z
Github GHSA