CVE-2025-13033
Unknown Unknown - Not Provided
BaseFortify

Publication date: 2025-11-14

Last updated on: 2026-03-04

Assigner: Red Hat, Inc.

Description
A vulnerability was identified in the email parsing library due to improper handling of specially formatted recipient email addresses. An attacker can exploit this flaw by crafting a recipient address that embeds an external address within quotes. This causes the application to misdirect the email to the attacker's external address instead of the intended internal recipient. This could lead to a significant data leak of sensitive information and allow an attacker to bypass security filters and access controls.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2025-11-14
Last Modified
2026-03-04
Generated
2026-05-07
AI Q&A
2025-11-14
EPSS Evaluated
2026-05-05
NVD
Affected Vendors & Products
Showing 2 associated CPEs
Vendor Product Version / Range
nodemailer nodemailer 7.0.6
nodemailer nodemailer 7.0.7
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-436 Product A handles inputs or steps differently than Product B, which causes A to perform incorrect actions based on its perception of B's state.
CWE-1286 The product receives input that is expected to be well-formed - i.e., to comply with a certain syntax - but it does not validate or incorrectly validates that the input complies with the syntax.
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?

This vulnerability exists in an email parsing library where specially crafted recipient email addresses containing an external address within quotes cause the application to misdirect emails. Instead of delivering the email to the intended internal recipient, the email is sent to the attacker's external address.


How can this vulnerability impact me? :

The vulnerability can lead to significant data leaks of sensitive information by sending emails to unauthorized external recipients. It also allows attackers to bypass security filters and access controls, potentially exposing confidential data.


Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70
EPSS Chart