← Vulnerability feed

Vulnerability record · CVE-2025-13033 · published 14 November 2025

CVE-2025-13033: A vulnerability was identified in the email parsing library due to improper handling of specially formatted re…

A vulnerability was identified in the email parsing library due to improper handling of specially formatted recipient email addresses. An attacker can exploit this flaw by crafting a recipient address that embeds an external address within quotes. This causes the application to misdirect the email to the attacker's external address instead of the intended internal recipient. This could lead to a significant data leak of sensitive information and allow an attacker to bypass security filters and access controls.

7.5 CVSS 3.1 High EPSS 0.54% · top 57.1% CWE-1286 · CWE-1286 Deferred
7.5CVSS 3.1 base score
0.54%EPSS exploitation probability, 30 days
NoNot in CISA KEV
0Affected product versions listed by NVD
7References
17 Jun 2026Last modified by NVD

Description

A vulnerability was identified in the email parsing library due to improper handling of specially formatted recipient email addresses. An attacker can exploit this flaw by crafting a recipient address that embeds an external address within quotes. This causes the application to misdirect the email to the attacker's external address instead of the intended internal recipient. This could lead to a significant data leak of sensitive information and allow an attacker to bypass security filters and access controls.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

References

Track CVE-2025-13033 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Source: NIST National Vulnerability Database (record CVE-2025-13033), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.