Junglewise Threat Intelligence

CVE-2026-57511: SuperPlane SMTP header injection in webhook event title

CVE-2026-57511 · Severity: medium · CVSS 5.4 · Published 2026-07-28

Executive brief

SuperPlane, an automation and workflow platform, was vulnerable to a security flaw in how it handles email notifications. An unauthenticated attacker could exploit this to send fraudulent emails that appear to come from trusted addresses or secretly redirect copies of sensitive automated alerts to their own accounts. This could lead to data theft, successful phishing attacks against employees, or the bypassing of email security filters.

Technical details

An SMTP header injection vulnerability exists in SuperPlane versions prior to 0.30.0 due to improper neutralization of CRLF sequences (CWE-93) in the event payload title field. When this field is processed via a webhook and subsequently used in an SMTP DATA command, an unauthenticated attacker can inject arbitrary headers. This allows for various malicious actions, including adding Bcc recipients for data exfiltration, spoofing the 'From' address to bypass SPF/DKIM protections, or modifying Content-Type and MIME boundaries to alter the message body for phishing. The issue was addressed in version 0.30.0 by sanitizing outgoing SMTP headers.

Affected products

  • superplanehq SuperPlane < 0.30.0

Timeline

  • 2026-07-25: patched: Fix committed to repository
  • 2026-07-27: patched: Version 0.30.0 released
  • 2026-07-28: disclosed: CVE published

References

Related threats