Impact
aiosmtplib is a Python library that sends email via SMTP. In versions prior to 5.1.3 it does not validate email address inputs that are supplied to the MAIL FROM and RCPT TO commands. Attackers can craft addresses containing spaces and angle brackets to embed ESMTP parameters such as AUTH, NOTIFY, or ORCPT, allowing them to forge a sender identity or redirect delivery notifications to arbitrary third parties. execution but compromises the integrity of email delivery and can be used for spoofing and notification abuse.
Affected Systems
The product aiosmtplib, maintained by cole, is vulnerable in all releases before version 5.1.3. The fix that sanitizes address inputs is available in v5.1.3 and later.
Risk and Exploitability
The moderate CVSS score of 6.3 indicates that the vulnerability mainly impacts integrity. The EPSS score of less than 1 % and the fact that it is not listed in the CISA KEV suggest that exploitation is unlikely to be widespread. The likely attack vector requires only the ability to invoke the library with a crafted address; no additional privileges or network access beyond normal SMTP usage appear to be necessary.
OpenCVE Enrichment