Versions of the package mailparser before 3.9.3 are vulnerable to Cross-site Scripting (XSS) via the textToHtml() function due to the improper sanitisation of URLs in the email content. An attacker can execute arbitrary scripts in victim browsers by adding extra quote " to the URL with embedded malicious JavaScript code.
Metrics
Affected Vendors & Products
References
History
Tue, 03 Mar 2026 05:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Versions of the package mailparser before 3.9.3 are vulnerable to Cross-site Scripting (XSS) via the textToHtml() function due to the improper sanitisation of URLs in the email content. An attacker can execute arbitrary scripts in victim browsers by adding extra quote " to the URL with embedded malicious JavaScript code. | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: snyk
Published:
Updated: 2026-03-03T05:00:11.753Z
Reserved: 2026-03-02T18:41:43.509Z
Link: CVE-2026-3455
No data.
Status : Received
Published: 2026-03-03T05:17:25.240
Modified: 2026-03-03T05:17:25.240
Link: CVE-2026-3455
No data.
OpenCVE Enrichment
No data.