Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-3455

22
FAUCET Score

CVE-2026-3455 is a Cross-site Scripting (XSS) vulnerability found in mailparser versions prior to 3.9.3, specifically within the textToHtml() function. This flaw allows an attacker to inject malicious JavaScript into a victim's browser by manipulating URLs in email content with improper sanitization. Rated as Medium severity (CVSS 6.1), it requires user interaction (UI:R) but can be exploited remotely (AV:N) with low attack complexity (AC:L), potentially leading to limited confidentiality and integrity impacts (C:L, I:L). There is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion, though it has received some media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
< 3.9.3CPE matchmatch criteria
cpe:2.3:a:nodemailer:mailparser:*:*:*:*:*:node.js:*:*

CVSS Data

CVSS version used by this source: 4.0

2.0LOW

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:L/SI:L/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
NETWORK
Attack Complexity
LOW
Attack Requirements
NONE
Privileges Required
NONE
User Interaction
ACTIVE
VS Confidentiality
NONE
VS Integrity
LOW
VS Availability
NONE
SS Confidentiality
LOW
SS Integrity
LOW
SS Availability
NONE
Exploit Maturity
PROOF_OF_CONCEPT
CvssVersion
4.0

Exploit Intelligence

EPSS Score
0.31%
Probability of exploitation in next 30 days
EPSS Percentile
23.4%
Percentile rank of EPSS score among Peer Group
As of 2026-07-26
Model: v2026.06.15
This CVE's current EPSS score of 0.0031 is in the 24th percentile among its peer group of 26,219 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (2)

github_advisorypatch availablevia nvd_reference
View patch
npmpatch availablevia ghsa
Product: mailparserFixed in: 3.9.3

Vendor Advisories (1)

npmGHSA-7gmj-h9xc-mcxclow

mailparser vulnerable to Cross-site Scripting

Mar 3, 2026

References

gist.github.com / hayageek/7fcb225e3b1ea9a341d560403fbb585a
ExploitThird Party Advisory
github.com / nodemailer/mailparser/commit/921a67df4cfb38f0b411037d7b26fbd4d5411b08
Patch
github.com / nodemailer/mailparser/issues/412
Issue Tracking
security.snyk.io / vuln/SNYK-JS-MAILPARSER-15204032
Third Party Advisory