CVE-2025-13033 - CVE House
Back to Database
Status published High CVE-2025-13033

Nodemailer: nodemailer: email to an unintended domain can occur due to interpretation conflict

Vulnerability Description

A vulnerability was identified in the email parsing library due to improper handling of specially formatted recipient email addresses. An attacker can exploit this flaw by crafting a recipient address that embeds an external address within quotes. This causes the application to misdirect the email to the attacker's external address instead of the intended internal recipient. This could lead to a significant data leak of sensitive information and allow an attacker to bypass security filters and access controls.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-13033

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

nodemailer, Red Hat Ceph Storage 8.1, Red Hat Developer Hub 1.9, Red Hat Advanced Cluster Management for Kubernetes 2
Vulnerable Versions:
0, 1777566546, 1772573159

Timeline

Official Publish: November 14th, 2025
Last Modified: May 11th, 2026
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Weaknesses (CWE)

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.