MEDIUM 5.3 NVD
CVE-2026-82660
Nodemailer before 8.0.9 fails to enforce disableFileAccess and disableUrlAccess options during message normalization in jsonTransport. Attackers can read local
Nodemailer before 8.0.9 fails to enforce disableFileAccess and disableUrlAccess options during message normalization in jsonTransport. Attackers can read local files or fetch URLs by supplying path or href values in message content fields, bypassing intended access controls.
References
- https://github.com/nodemailer/nodemailer/security/advisories/GHSA-wqvq-jvpq-h66f
- https://www.vulncheck.com/advisories/nodemailer-jsontransport-bypasses-disablefileaccess-a
- https://github.com/nodemailer/nodemailer/security/advisories/GHSA-wqvq-jvpq-h66f
This medium severity vulnerability with a CVSS score of 5.3 was published on 2026-08-31 via NVD.
vulnfeed aggregates 11521 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.