Back to overview

CVE-2026-57511

MEDIUM
5.4
CVSS 3.1
Description
SuperPlane before 0.30.0 contains an SMTP header injection vulnerability that allows unauthenticated attackers to inject arbitrary SMTP headers by including CRLF sequences in the event payload title field delivered via webhook. Attackers can manipulate the unsanitized title field passed to the SMTP DATA command to add Bcc recipients for content exfiltration, forge the From address to bypass SPF and DKIM checks, or inject Content-Type and MIME boundary headers to corrupt message bodies for phishing.

Metadata

CVE ID
CVE-2026-57511
State
PUBLISHED
Assigner
VulnCheck
Reserved
2026-06-24 15:58 UTC
Published
2026-07-28 19:09 UTC
Last updated
2026-07-28 19:09 UTC
Primary CWE
CWE-93
Improper Neutralization of CRLF Sequences ('CRLF Injection')
Vendor / Product
superplanehq / superplane
Sources
cve.org  ·  NVD

Severity & Metrics

5.4 MEDIUM CVSS 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N
Affected products (1)
VendorProductPlatformVersions
superplanehq superplane — 0 < 0.30.0
Weakness (CWE)
CWESourceDescription
CWE-93 cna Improper Neutralization of CRLF Sequences ('CRLF Injection')
CVSS scores (2)
ScoreSeverityVersionSourceVector
6.3 MEDIUM 4.0 cna CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N
5.4 MEDIUM 3.1 cna CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N
Back to overview