nodemailer 在 9.0.1 版本之前,未能将 和 标志应用于消息级别的 选项,使得经过身份验证的攻击者能够通过提供 或 属性,读取任意文件或执行服务器端请求伪造(SSRF)。攻击者可以通过构造包含文件路径或 URL 的原始消息来利用该漏洞,从而绕过预期的沙箱环境,并将获取到的内容通过外发邮件发送至攻击者控制的收件人。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| nodemailer | nodemailer | 0 ~ 9.0.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-82854 | 9.8 CRITICAL | Nodemailer before 8.0.3 SMTP Command Injection via envelope.size |
| CVE-2026-82662 | 6.5 MEDIUM | Nodemailer before 8.0.8 TLS Certificate Validation Bypass |
| CVE-2026-82660 | 5.4 MEDIUM | Nodemailer jsonTransport bypasses disableFileAccess and disableUrlAccess |
| CVE-2026-82661 | 5.4 MEDIUM | Nodemailer CRLF Injection via List-* Header Comments |
| CVE-2024-58379 | 5.3 MEDIUM | nodemailer before 6.9.9 ReDoS via attachDataUrls parameter |
| CVE-2026-82853 | 4.9 MEDIUM | Nodemailer before 8.0.5 SMTP Command Injection via CRLF |
No comments yet