Executive brief
Mailgen is a popular Node.js library for generating transactional emails in both HTML and plaintext formats. A flaw in the plaintext email generator allows attackers to inject HTML code and bypass filters when user-controlled content is processed, potentially enabling malicious scripts to be embedded in plaintext emails.
Technical details
The vulnerability is an HTML injection flaw in the generatePlaintext() function caused by incorrect filter ordering. The code first converts HTML break tags to newlines, then attempts to strip all HTML tags with a regex. By nesting an HTML tag inside a break tag (e.g., <img<br> src=xyz onerror=alert(1)>), attackers can bypass the HTML tag removal regex. The vulnerability requires the application to pass user-generated content directly to generatePlaintext() without prior sanitization. An attacker can inject JavaScript payloads that execute in email clients supporting HTML rendering. The issue was patched in version 2.0.30 (commit 741a019).
Affected products
- Mailgen Mailgen < 2.0.30
Timeline
- 2025-09-22: disclosed
- 2025-09-22: patched: Version 2.0.30 released to npm