Impact
An unhandled exception is triggered in the uri‑js library when the URI.parse function processes a malformed mailto link. The flaw lies in src/schemes/mailto.ts and is classified as Unhandled Exception (CWE‑248). When invoked with crafted input the library throws an uncaught exception, causing the host application to crash. The flaw can be triggered remotely as exploit code is publicly available.
Affected Systems
The vulnerability affects all installations of the garycourt uri‑js package up to and including version 4.4.1. It is part of the Mailto Header Handler module that parses mailto schemes. JavaScript, Node.js, and any downstream projects that depend on uri‑js without updating to a newer release are exposed. The vendor is the original author, Gary Courtney.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate risk. EPSS is not provided and the vulnerability is not listed in the CISA KEV catalog. Attackers can exploit the flaw by sending crafted mailto links to components that load uri‑js over a network‑accessible interface. When the library processes the malformed input it throws an uncaught exception, causing the host application to crash and leading to a denial of service. The description does not specify any requirement for authentication or privileged access.
OpenCVE Enrichment