Executive brief
Mailgen is a Node.js library that generates formatted email messages. An HTML injection vulnerability allows attackers to inject malicious HTML code (including XSS payloads) into plaintext emails by encoding HTML tags, which bypasses the library's sanitization filter. If the resulting plaintext output is rendered as HTML in a browser, an attacker can steal sensitive information or execute arbitrary code in the victim's browser context.
Technical details
The vulnerability is a classic encoding-based XSS filter bypass in the `generatePlaintext()` method. The vulnerable function attempts to strip HTML tags using a regex pattern that matches literal `<` and `>` characters, but it fails when these characters are HTML-encoded (e.g., `<` and `>`). The function then decodes HTML entities at the end, converting the encoded tags back into executable HTML. An attacker can inject a payload like `&ltimg src=x onerror=alert(1)&gt` into email fields, which passes through the filter as text but becomes valid HTML when rendered. The attack requires the application to use `generatePlaintext()` with user-supplied input and then render the output as HTML. Versions 2.0.30 and earlier are affected; version 2.0.31 includes a fix.
Affected products
- Mailgen Mailgen <=2.0.30
Timeline
- 2025-10-14: disclosed
- 2025-10-14: patched: Fix released in version 2.0.31