GHSA-jvvf-x445-j334

Suggest an improvement
Source
https://github.com/advisories/GHSA-jvvf-x445-j334
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-jvvf-x445-j334/GHSA-jvvf-x445-j334.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-jvvf-x445-j334
Aliases
Published
2026-09-29T23:51:16Z
Modified
2026-09-30T00:00:03Z
Severity
  • 4.8 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N CVSS Calculator
Summary
fast-uri vulnerable to mailto header injection via percent-encoded field-name desynchronization
Details

Impact

fast-uri's mailto scheme parser compares each query field name to the reserved names (to, subject, body) while the name is still percent-encoded, and only percent-decodes it when storing it as a generic header. On serialize, the decoded name is re-emitted, so a field name such as %74o (percent-encoded to) is not recognized as a recipient at parse time (parse().to shows only the legitimate recipient) but materializes as a literal to= field after serialize(), and reparsing then treats it as a recipient. The same technique smuggles subject and body through %73ubject and %62ody.

An application that parses an untrusted mailto URI, makes a display, allowlist, or logging decision on parse().to, then re-serializes the result and passes the serialized string to a mail client or an outbound send path can gain an attacker-chosen recipient, subject, or body that was not visible when the recipient list was checked. A scanner inspecting the raw input for an extra to= sees nothing, because the injected field appears only after fast-uri serializes.

Patches

Upgrade to fast-uri 4.1.5.

Workarounds

Percent-decode and compare mailto field names case-insensitively before trusting parse().to, or re-check the recipient list on the serialized output rather than only on the initial parse, until upgrading.

Database specific
{
    "cwe_ids":  [
        "CWE-172",
        "CWE-436"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-09-29T23:51:16Z",
    "nvd_published_at":  "2026-09-15T11:17:12Z",
    "severity":  "MODERATE"
}
References

Affected packages

npm / fast-uri

Package

Affected ranges

Type
SEMVER
Events
Introduced
4.1.3
Fixed
4.1.5

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-jvvf-x445-j334/GHSA-jvvf-x445-j334.json"