PT-2026-65576 · Unknown · Superplane

·

CVE-2026-57511

·

Published

2026-07-28

·

Updated

2026-07-28

CVSS v4.0

6.3

Medium

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N
Name of the Vulnerable Software and Affected Versions SuperPlane versions prior to 0.30.0
Description An SMTP header injection issue exists where unauthenticated attackers can inject arbitrary SMTP headers by including CRLF (Carriage Return Line Feed) sequences in the event payload title field delivered via webhook. By manipulating the unsanitized title field passed to the SMTP DATA command, attackers can add Bcc recipients for content exfiltration, forge the From address to bypass SPF (Sender Policy Framework) and DKIM (DomainKeys Identified Mail) checks, or inject Content-Type and MIME boundary headers to corrupt message bodies for phishing purposes.
Recommendations Update SuperPlane to version 0.30.0 or later.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-57511

Affected Products

Superplane