Listen to this Post
Nodemailer’s address parser can produce an unexpected recipient address when an RFC 5322 comment follows the domain of an address whose local-part is a quoted string. For example, the input `”user”@example.com(x)evil.com` is parsed as { address: "[email protected] evil.com", name: "" }. The resulting address therefore contains additional attacker-controlled domain text separated by a literal space. The parsed `.address` value is subsequently propagated into the SMTP envelope: `src/addressparser/index.ts` → `recipient.address` → `src/mime-node/index.ts` → envelope.to. The envelope construction uses the parsed address without another strict address validation step. This appears to be a variant of the RFC 5322 comment parsing issue addressed by GHSA-cc9r-2j5m-2m83, but it follows a different parser path when the local-part is quoted. The issue is caused by different parsing behavior for quoted and unquoted local-parts. The quoted-local-part variant allows the comment-separated trailing domain atoms to remain in the resulting `.address` value. That value is then used when constructing the message envelope: envelope.to = recipients.map(to => to.address as string). No additional strict recipient validation is performed at this boundary. The confirmed impact is that attacker-controlled comment content can result in a malformed/ambiguous recipient address being accepted by the parser and propagated into envelope.to. The reporter did not confirm successful delivery to an unintended recipient through a real SMTP server using this exact quoted-local-part variant. The remaining question is how real SMTP servers and other Nodemailer transports handle an envelope recipient containing a value such as [email protected] evil.com. An end-to-end SMTP test is required to determine whether this parser behavior results in an exploitable delivery or recipient-validation bypass. This report is intended as a potential variant/follow-up to GHSA-cc9r-2j5m-2m83. The existing advisory addresses RFC 5322 comment handling in email domains. This report identifies a separate parser path involving quoted local-parts that can preserve additional domain-like content in the normalized address. Please evaluate whether this behavior is already covered by the existing fix or represents a remaining parser variant. The parser should consistently reject or correctly terminate addresses containing trailing domain atoms after RFC 5322 comments, regardless of whether the local-part is quoted. The envelope-generation layer should also avoid assuming that a parser-produced address is safe for SMTP delivery without appropriate validation.
DailyCVE Form:
Platform: Nodemailer
Version: 9.1.0-10.0.8
Vulnerability: Envelope Recipient
Severity: Medium
date: 2026-09-26
Prediction: 2026-09-26
What Undercode Say:
Install vulnerable version npm install [email protected] Test the parser node -e "const nodemailer = require('nodemailer'); const parser = require('nodemailer/lib/addressparser'); console.log(parser('\"user\"@example.com(x)evil.com'));"
// Vulnerable code path in src/addressparser/index.ts const address = "[email protected] evil.com"; const envelope = { to: [bash] // No strict validation };
Exploit: (Educational Purposes!)
// Craft a malicious recipient address const maliciousAddress = '"user"@legitimate.com(x)attacker.com'; // The parser will produce an ambiguous envelope recipient const parsed = addressparser(maliciousAddress); // parsed[bash].address === "[email protected] attacker.com" // This value is used directly in the SMTP envelope envelope.to = parsed.map(p => p.address);
Protection: from this CVE
Upgrade to patched version npm install [email protected]
// Validate addresses after parsing
const parsed = addressparser(input);
const isValid = parsed.every(p => /^[^\s@]+@[^\s@]+.[^\s@]+$/.test(p.address));
if (!isValid) throw new Error('Invalid recipient address');
Impact:
Potential email misdelivery, recipient-validation bypass, and ambiguity in logging/auditing systems.
🎯Let’s Practice Exploiting & Learn Patching For Free:
🎓 Live Courses & Certifications:
Join Undercode Academy for Verified Certifications
🚀 Request a Custom Project:
Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands
Sources:
Reported By: github.com
Extra Source Hub:
Undercode

