CVE Feed

    Dashboard / CVE / CVE-2026-3455

    CVE-2026-3455

    Versions of the package mailparser before 3.9.3 are vulnerable to Cross-site Scripting (XSS) via the textToHtml() function due to the improper sanitisation of URLs in the email content. An attacker can execute arbitrary scripts in victim browsers by adding extra quote " to the URL with embedded malicious JavaScript code.

    Published:Mar 3, 2026
    Last Modified:Apr 17, 2026
    EPS:Mar 3, 2026
    EPSS Score:0.00049
    CVSS Score:6.1

    Affected Products

    Vendor
    Nodemailer
    Product
    Mailparser

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High