github.com/wneessen/go-mail is vulnerable to Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
20
Low Risk
Affected versions of this package fail to properly sanitize filenames for attachments and embedded files. This oversight allows control characters (such as newlines) and special characters (e.g., backslashes or quotes) to interfere with MIME headers and file system operations. In particular, the inclusion of newline characters in filenames introduces potential vulnerabilities, such as breaking MIME structure, enabling command injection, or causing unexpected behavior in systems that process filenames.
You are affected if you are using a version that falls within the vulnerable range.
github.com/wneessen/go-mail is vulnerable to Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') in versions 0.1.0 - 0.5.2.
Upgrade the github.com/wneessen/go-mail library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant