Количество 3
Количество 3
CVE-2025-59526
No description is available for this CVE.
CVE-2025-59526
mailgen is a Node.js package that generates responsive HTML e-mails for sending transactional mail. Prior to version 2.0.30, there is an HTML injection vulnerability in plaintext e-mails generated by Mailgen. Projects are affected if the Mailgen.generatePlaintext(email) method is used and given user-generated content. This vulnerability has been patched in version 2.0.30. A workaround involves stripping all HTML tags before passing any content into Mailgen.generatePlaintext(email).
GHSA-j2xj-h7w5-r7vp
Mailgen: HTML injection vulnerability in plaintext e-mails
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2025-59526 No description is available for this CVE. | 0% Низкий | 3 месяца назад | ||
CVE-2025-59526 mailgen is a Node.js package that generates responsive HTML e-mails for sending transactional mail. Prior to version 2.0.30, there is an HTML injection vulnerability in plaintext e-mails generated by Mailgen. Projects are affected if the Mailgen.generatePlaintext(email) method is used and given user-generated content. This vulnerability has been patched in version 2.0.30. A workaround involves stripping all HTML tags before passing any content into Mailgen.generatePlaintext(email). | 0% Низкий | 3 месяца назад | ||
GHSA-j2xj-h7w5-r7vp Mailgen: HTML injection vulnerability in plaintext e-mails | CVSS3: 5.3 | 0% Низкий | 3 месяца назад |
Уязвимостей на страницу