Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-28mw-fm9r-fxjg

Опубликовано: 31 авг. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 5.3
CVSS3: 5.4

Описание

Nodemailer before 8.0.9 fails to enforce disableFileAccess and disableUrlAccess options during message normalization in jsonTransport. Attackers can read local files or fetch URLs by supplying path or href values in message content fields, bypassing intended access controls.

Nodemailer before 8.0.9 fails to enforce disableFileAccess and disableUrlAccess options during message normalization in jsonTransport. Attackers can read local files or fetch URLs by supplying path or href values in message content fields, bypassing intended access controls.

EPSS

Процентиль: 9%
0.00189
Низкий

5.3 Medium

CVSS4

5.4 Medium

CVSS3

Дефекты

CWE-862

Связанные уязвимости

CVSS3: 5.4
ubuntu
16 дней назад

Nodemailer before 8.0.9 fails to enforce disableFileAccess and disableUrlAccess options during message normalization in jsonTransport. Attackers can read local files or fetch URLs by supplying path or href values in message content fields, bypassing intended access controls.

CVSS3: 5.4
redhat
16 дней назад

Nodemailer before 8.0.9 fails to enforce disableFileAccess and disableUrlAccess options during message normalization in jsonTransport. Attackers can read local files or fetch URLs by supplying path or href values in message content fields, bypassing intended access controls.

CVSS3: 5.4
nvd
16 дней назад

Nodemailer before 8.0.9 fails to enforce disableFileAccess and disableUrlAccess options during message normalization in jsonTransport. Attackers can read local files or fetch URLs by supplying path or href values in message content fields, bypassing intended access controls.

CVSS3: 5.4
debian
16 дней назад

Nodemailer before 8.0.9 fails to enforce disableFileAccess and disable ...

EPSS

Процентиль: 9%
0.00189
Низкий

5.3 Medium

CVSS4

5.4 Medium

CVSS3

Дефекты

CWE-862