Listen to this Post
fast-uri is a dependency-free RFC 3986 URI parser for Node.js, used by Fastify and ajv. The mailto scheme parser was added in version 4.1.3. In versions 4.1.3 and 4.1.4, the mailto parser compares each query field name to the reserved names (to, subject, body) while the name is still percent-encoded, and only percent-decodes it when storing it as a generic header. On serialize, the decoded name is re-emitted, so a field name such as %74o (percent-encoded “to”) is not recognized as a recipient at parse time (parse().to shows only the legitimate recipient) but materializes as a literal to= field after serialize(), and reparsing then treats it as a recipient. The same technique smuggles subject and body through %73ubject and %62ody. An application that parses an untrusted mailto URI, makes a display, allowlist, or logging decision on parse().to, then re-serializes the result and passes the serialized string to a mail client or an outbound send path can gain an attacker-chosen recipient, subject, or body that was not visible when the recipient list was checked. A scanner inspecting the raw input for an extra to= sees nothing, because the injected field appears only after fast-uri serializes. The vulnerability is classified as CWE-172 (Encoding Error) and CWE-436 (Interpretation Conflict). The CVSS v3.1 score is 4.8 (Medium) with vector CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N. The issue is fixed in fast-uri 4.1.5, and users should upgrade to 4.1.5 or later. As a workaround, do not act on a mailto URI that fast-uri has re-serialized without first decoding and re-validating its recipient, subject, and body fields. Percent-decode and compare mailto field names case-insensitively before trusting parse().to, or re-check the recipient list on the serialized output rather than only on the initial parse, until upgrading.
DailyCVE Form:
Platform: fast-uri Node.js
Version: 4.1.3 4.1.4
Vulnerability: mailto header injection
Severity: Medium
date: 2026-09-15
Prediction: 2026-09-15
What Undercode Say
Analytics:
Check installed fast-uri version npm list fast-uri Update to patched version npm install [email protected]
// PoC: Parse, inspect, serialize, re-parse
const fastUri = require('fast-uri');
const malicious = 'mailto:[email protected]?%[email protected]&subject=Hello';
const parsed = fastUri.parse(malicious);
console.log('Initial parse().to:', parsed.to);
// Output: '[email protected]' (attacker not visible)
const serialized = fastUri.serialize(parsed);
console.log('Serialized:', serialized);
// Output: 'mailto:[email protected][email protected]&subject=Hello'
const reparsed = fastUri.parse(serialized);
console.log('Re-parsed .to:', reparsed.to);
// Output: '[email protected],[email protected]'
Exploit: (Educational Purposes!)
A crafted mailto URI such as `mailto:[email protected]?%[email protected]&%73ubject=Phishing&%62ody=Click+here` is parsed by fast-uri 4.1.3 or 4.1.4. The initial `parse().to` returns only [email protected]. After serialize(), the output becomes mailto:[email protected][email protected]&subject=Phishing&body=Click+here. Re-parsing this serialized string yields an additional recipient [email protected], along with smuggled subject and body content. An application that validates the recipient list from the first parse and then sends the serialized URI will silently deliver the message to the attacker-chosen recipient.
Protection: from this CVE
Upgrade to fast-uri 4.1.5 or later. As an immediate workaround, percent-decode and compare mailto field names case-insensitively before trusting parse().to, or re-check the recipient list on the serialized output rather than only on the initial parse. Do not act on a mailto URI that fast-uri has re-serialized without first decoding and re-validating its recipient, subject, and body fields.
Impact
An unauthenticated attacker can inject attacker-chosen email recipients, subjects, and body content into a mailto URI processed by vulnerable versions of fast-uri. Applications that make display, allowlist, or logging decisions based on the initial parsed recipient list and then re-serialize and send the URI are vulnerable to recipient injection, subject smuggling, and body smuggling. This can lead to unauthorized communication, phishing campaigns, and bypass of security monitoring that relies on parsed fields. The vulnerability has a CVSS v3.1 base score of 4.8 (Medium) and a CVSS v4 score of 6.3 (Medium).
🎯Let’s Practice Exploiting & Learn Patching For Free:
🎓 Live Courses & Certifications:
Join Undercode Academy for Verified Certifications
🚀 Request a Custom Project:
Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands
Sources:
Reported By: github.com
Extra Source Hub:
Undercode

