CVE-2026-92595
CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N
Summary
Nodemailer (npm package nodemailer) versions 9.1.0 and earlier do not honor the disableFileAccess and disableUrlAccess sandbox options when message content is resolved through the public plugin API MailMessage.resolveContent() using the documented legacy three-argument signature resolveContent(data, key, callback). Because shared.resolveContent() normalizes the missing options argument to an empty object, the message-level flags copied into mail.data by the MailMessage constructor are discarded, and resolveContentValue() skips both access-control checks, reaching nmfetch(url) or fs.createReadStream(path). As a result, plugin or application code that resolves untrusted message content (html, text, attachment path or href) via this API can be induced to read arbitrary local files or issue outbound HTTP(S) requests (server-side request forgery), bypassing the sandbox the application enabled. The internal paths used by transporter.sendMail() (resolveAll(), _convertDataImages(), and the MIME streaming path) are not affected. Fixed in version 9.1.1.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| nodemailer | nodemailer | 0 < 9.1.1 | affected |
| nodemailer | nodemailer | 9.1.1 | unaffected |
Weaknesses
- CWE-73: External Control of File Name or Path
References
- https://github.com/nodemailer/nodemailer/security/advisories/GHSA-8m3c-c648-2xjj
- https://www.vulncheck.com/advisories/nodemailer-before-9.1.1-security-sandbox-bypass-via-resolvecontent
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.