SMTP Header Injection Vulnerability in SuperPlane by SuperPlaneHQ
CVE-2026-57511
6.3MEDIUM
What is CVE-2026-57511?
SuperPlane versions prior to 0.30.0 are affected by an SMTP header injection vulnerability that allows unauthenticated attackers to inject arbitrary SMTP headers via CRLF sequences. This vulnerability occurs when attackers manipulate the unsanitized event payload title field sent through webhooks, potentially enabling them to add Bcc recipients for content exfiltration. Furthermore, attackers can forge the From address, bypassing security mechanisms like SPF and DKIM checks, or inject malicious Content-Type and MIME boundary headers, which could corrupt the message body and facilitate phishing attacks.
Affected Version(s)
superplane 0
