Improper Neutralization of Special Elements Used in a Template Engine Affecting fof/pretty-mail package, versions >=0.0.0


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

Exploit Maturity
Proof of Concept
EPSS
0.03% (9th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-PHP-FOFPRETTYMAIL-14413474
  • published14 Dec 2025
  • disclosed11 Dec 2025
  • creditChokri Hammedi

Introduced: 11 Dec 2025

CVE-2024-58303  (opens in a new tab)
CWE-1336  (opens in a new tab)

How to fix?

There is no fixed version for fof/pretty-mail.

Overview

fof/pretty-mail is a Create HTML email for Flarum

Affected versions of this package are vulnerable to Improper Neutralization of Special Elements Used in a Template Engine via the email template processing. An authenticated attacker with admin privileges can execute arbitrary system commands by injecting crafted template expressions during email generation.

CVSS Base Scores

version 4.0
version 3.1