Impact
The vulnerable fast‑uri library’s mailto parser compares query field names against reserved keys such as to, subject, and body while the names remain percent‑encoded, and only decodes them when storing them as generic headers. Consequently, a percent‑encoded spelling of a reserved field is not noticed during initial parsing but is emitted verbatim when the URI is re‑serialized. An application that validates, logs, or displays recipients from the first parse and later re‑serializes the URI before sending can silently add an attacker‑chosen recipient, subject, or body, enabling email injection.
Affected Systems
The issue affects the fast‑uri library used by Fastify, ajv, and other Node.js projects. Vulnerable releases are 4.1.3 and 4.1.4; version 4.1.5 and later contain the fix.
Risk and Exploitability
The CVSS score of 4.8 classifies the flaw as moderate severity. The EPSS value of <1% indicates a low probability of exploitation at the present time, and the vulnerability is not listed in the CISA KEV catalog. Attackers must provide a crafted mailto URL, which the application parses, stores, and later re‑serializes for outbound email. The flaw is a logic error rather than an externally exploitable network vulnerability, but any code that accepts user‑supplied mailto links without re‑validation is at risk of covert recipient injection.
OpenCVE Enrichment
Github GHSA