Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-82660

Опубликовано: 31 авг. 2026
Источник: debian

Описание

Nodemailer before 8.0.9 fails to enforce disableFileAccess and disableUrlAccess options during message normalization in jsonTransport. Attackers can read local files or fetch URLs by supplying path or href values in message content fields, bypassing intended access controls.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
node-nodemailerfixed8.0.11+~8.0.1-1package
node-nodemailerno-dsatrixiepackage
node-nodemailerpostponedbookwormpackage

Примечания

  • https://github.com/nodemailer/nodemailer/security/advisories/GHSA-wqvq-jvpq-h66f

Связанные уязвимости

CVSS3: 5.4
ubuntu
16 дней назад

Nodemailer before 8.0.9 fails to enforce disableFileAccess and disableUrlAccess options during message normalization in jsonTransport. Attackers can read local files or fetch URLs by supplying path or href values in message content fields, bypassing intended access controls.

CVSS3: 5.4
redhat
16 дней назад

Nodemailer before 8.0.9 fails to enforce disableFileAccess and disableUrlAccess options during message normalization in jsonTransport. Attackers can read local files or fetch URLs by supplying path or href values in message content fields, bypassing intended access controls.

CVSS3: 5.4
nvd
16 дней назад

Nodemailer before 8.0.9 fails to enforce disableFileAccess and disableUrlAccess options during message normalization in jsonTransport. Attackers can read local files or fetch URLs by supplying path or href values in message content fields, bypassing intended access controls.

CVSS3: 5.4
github
16 дней назад

Nodemailer before 8.0.9 fails to enforce disableFileAccess and disableUrlAccess options during message normalization in jsonTransport. Attackers can read local files or fetch URLs by supplying path or href values in message content fields, bypassing intended access controls.