PT-2026-22720 · Unknown · Mail-Parser
Ravishanker Kusuma
·
Published
2026-03-03
·
Updated
2026-03-13
·
CVE-2026-3455
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
mailparser versions prior to 3.9.3
Description
The package mailparser is susceptible to Cross-site Scripting (XSS) due to insufficient sanitization of URLs within email content. Specifically, the
textToHtml() function does not properly handle URLs, allowing an attacker to inject malicious JavaScript code by adding extra quotes to the URL. This can lead to the execution of arbitrary scripts in a victim's browser.Recommendations
Update mailparser to version 3.9.3 or later.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mail-Parser