PT-2026-65576 · Unknown · Superplane
CVSS v4.0
6.3
Medium
| Vector | AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N |
Name of the Vulnerable Software and Affected Versions
SuperPlane versions prior to 0.30.0
Description
An SMTP header injection issue exists where unauthenticated attackers can inject arbitrary SMTP headers by including CRLF (Carriage Return Line Feed) sequences in the event payload title field delivered via webhook. By manipulating the unsanitized title field passed to the SMTP DATA command, attackers can add Bcc recipients for content exfiltration, forge the From address to bypass SPF (Sender Policy Framework) and DKIM (DomainKeys Identified Mail) checks, or inject Content-Type and MIME boundary headers to corrupt message bodies for phishing purposes.
Recommendations
Update SuperPlane to version 0.30.0 or later.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Superplane