GHSA-g57g-f23g-4646
## Summary Nodemailer's address parser can produce an unexpected recipient address when an RFC 5322 comment follows the domain of an address whose local-part is a quoted string. For example: ```text "user"@example.com(x)evil.com ``` is parsed as: ```text { address: "[email protected] evil.com", name: "" } ``` The resulting address therefore contains additional attacker-controlled domain text separated by a literal space. The parsed `.address` value is subsequently propagated into the SMTP envelope: ```text src/addressparser/index.ts ↓ recipient.address ↓ src/mime-node/index.ts ↓ envelope.to ``` The envelope construction uses the parsed address without another strict address validation step. This appears to be a variant of the RFC 5322 comment parsing issue addressed by GHSA-cc9r-2j5m-2m83, but it follows a different parser path when the local-part is quoted. ## Reproduction Input: ```text "user"@example.com(x)evil.com ``` Observed parser output: ```text address: "[email protected] evil.com" name: "" ``` A second example: ```text "a"@b.com(c)d.com(e)f.com ``` produces: ```text address: "[email protected] d.com f.com" name: "" ``` For comparison, the corresponding unquoted form: ```text [email protected](x)evil.com ``` takes a different code path and is handled by the existing protection differently. ## Technical Details The issue is caused by different parsing behavior for quoted and unquoted local-parts. The quoted-local-part variant allows the comment-separated trailing domain atoms to remain in the resulting `.address` value. That value is then used when constructing the message envelope: ```text envelope.to = recipients.map(to => to.address as string) ``` No additional strict recipient validation is performed at this boundary. ## Security Impact The confirmed impact is that attacker-controlled comment content can result in a malformed/ambiguous recipient address being accepted by the parser and propagated into `envelop
Properties
- severity
- medium
- summary
- Nodemailer: Quoted local-part can produce malformed envelope recipient through RFC 5322 comment parsing
- cvss_score
- 5.3
- retrieved_at
- 2026-09-30T02:27:15+00:00
- ghsa_published
- 2026-09-29T23:44:04Z
- source_url
- https://github.com/advisories/GHSA-g57g-f23g-4646
- ghsa_updated
- 2026-09-29T23:44:05Z
- ghsa_id
- GHSA-g57g-f23g-4646
- last_source
- GitHub Advisory Database
- cve_id
- GHSA-g57g-f23g-4646
- cvss_vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
- signal_observed_at
- 2026-09-30T02:27:15+00:00
- is_ghsa_only
- true
Related Entities (5)
AFFECTS (1)
HAS_WEAKNESS (2)
REPORTED_BY (1)
VULNERABLE_TO (1)
Explore deeper with Ninja Signal's threat intelligence graph