Weakness in Mailto Header Handler of garycourt uri-js by garycourt
CVE-2026-103387
Key Information:
Badges
What is CVE-2026-103387?
A weakness exists in the Mailto Header Handler of garycourt's uri-js library up to version 4.4.1, specifically in the URI.parse function located in src/schemes/mailto.ts. This vulnerability can lead to uncaught exceptions due to improper handling of parsed arguments. An attacker may exploit this remotely, and the details of the exploit are publicly available. Despite being reported to the project earlier, there has been no response or action taken to address this issue.
Affected Version(s)
uri-js 4.4.0
uri-js 4.4.1
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
