PT-2025-47000 · Unknown+1 · Email Parsing Library+1

Published

2025-10-07

·

Updated

2026-05-11

·

CVE-2025-13033

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Email Parsing Library (affected versions not specified)
Description A flaw exists in the email parsing library related to how recipient email addresses are processed. Specifically, the library improperly handles specially formatted addresses, allowing an attacker to redirect emails intended for internal recipients to an external address controlled by the attacker. This is achieved by crafting a recipient address that includes an external address within quotes. Successful exploitation could result in a data leak of sensitive information and bypass security measures.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Weakness Enumeration

Related Identifiers

CVE-2025-13033
GHSA-JJ37-3377-M6VV
GHSA-MM7P-FCC7-PG87

Affected Products

Debian
Email Parsing Library