CVE-2026-82660
5.3
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
Summary
Nodemailer before 8.0.9 fails to enforce disableFileAccess and disableUrlAccess options during message normalization in jsonTransport. Attackers can read local files or fetch URLs by supplying path or href values in message content fields, bypassing intended access controls.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| nodemailer | nodemailer | 0 < 8.0.9 | affected |
| nodemailer | nodemailer | 8.0.9 | unaffected |
Weaknesses
- CWE-862: Missing Authorization
ADP Enrichment
CISA ADP Vulnrichment
- SSVC:
- Exploitation: poc
- Automatable: no
- Technical Impact: partial
Additional References
References
- https://github.com/nodemailer/nodemailer/security/advisories/GHSA-wqvq-jvpq-h66f
- https://www.vulncheck.com/advisories/nodemailer-jsontransport-bypasses-disablefileaccess-and-disableurlaccess
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.