HTML Injection Vulnerability in Mailgen Node.js Package by Elad Nava
CVE-2025-62380
What is CVE-2025-62380?
The Mailgen package for Node.js, used for creating responsive HTML emails, is susceptible to an HTML injection vulnerability in the generatePlaintext method. This issue arises when user-generated content includes certain Unicode characters that evade removal by the regular expressions intended to strip HTML tags. Consequently, the output can return unexpected HTML elements within emails expected to be plaintext, leading to potential execution of malicious scripts in recipient browsers. To mitigate this risk, it is crucial to avoid passing untrusted input to Mailgen.generatePlaintext and to upgrade to version 2.0.32, where this vulnerability is addressed.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
mailgen < 2.0.32
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
