GHSA-7gmj-h9xc-mcxc

Suggest an improvement
Source
https://github.com/advisories/GHSA-7gmj-h9xc-mcxc
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/03/GHSA-7gmj-h9xc-mcxc/GHSA-7gmj-h9xc-mcxc.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-7gmj-h9xc-mcxc
Aliases
Published
2026-03-03T06:31:14Z
Modified
2026-03-04T20:36:18.140900Z
Severity
  • 6.1 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N CVSS Calculator
  • 2.0 (Low) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:L/SI:L/SA:N/E:P CVSS Calculator
Summary
mailparser vulnerable to Cross-site Scripting
Details

Versions of the package mailparser before 3.9.3 are vulnerable to Cross-site Scripting (XSS) via the textToHtml() function due to the improper sanitisation of URLs in the email content. An attacker can execute arbitrary scripts in victim browsers by adding extra quote " to the URL with embedded malicious JavaScript code.

Database specific
{
    "github_reviewed": true,
    "cwe_ids": [
        "CWE-79"
    ],
    "github_reviewed_at": "2026-03-04T20:15:58Z",
    "nvd_published_at": "2026-03-03T05:17:25Z",
    "severity": "LOW"
}
References

Affected packages

npm / mailparser

Package

Affected ranges

Type
SEMVER
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.9.3

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/03/GHSA-7gmj-h9xc-mcxc/GHSA-7gmj-h9xc-mcxc.json"