CVE-2026-57511
MEDIUMSuperPlane < 0.30.0 SMTP Header Injection via Webhook Event Title
Title source: cnaDescription
SuperPlane before 0.30.0 contains an SMTP header injection vulnerability that allows unauthenticated attackers to inject arbitrary SMTP headers by including CRLF sequences in the event payload title field delivered via webhook. Attackers can manipulate the unsanitized title field passed to the SMTP DATA command to add Bcc recipients for content exfiltration, forge the From address to bypass SPF and DKIM checks, or inject Content-Type and MIME boundary headers to corrupt message bodies for phishing.
References (4)
Core 4
Core References
Release Notes release-notes
Release Notes
https://github.com/superplanehq/superplane/releases/tag/v0.30.0
Patch patch
Patch Commit
https://github.com/superplanehq/superplane/commit/428c559dd2fa0aef3ba825a434a1b05c9abc7df7
Third Party Advisory third-party-advisory
https://www.vulncheck.com/advisories/superplane-smtp-header-injection-via-webhook-event-title
Scores
CVSS v3
5.4
EPSS
0.0024
EPSS Percentile
14.7%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-93
Status
published
Products (1)
superplanehq/superplane
< 0.30.0
Published
Jul 28, 2026
Tracked Since
Jul 29, 2026