{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3anodemailernodemailer/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:nodemailer:nodemailer:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.1,"id":"CVE-2026-82659"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["nodemailer (\u003c 9.0.1)","Nodemailer (\u003c 8.0.4)"],"_cs_severities":["high"],"_cs_tags":["vulnerability","ssrf","file-access","smtp-injection","nodemailer"],"_cs_type":"advisory","_cs_vendors":["Nodemailer"],"content_html":"\u003cp\u003eNodemailer versions prior to 9.0.1 contain a security oversight where the 'disableFileAccess' and 'disableUrlAccess' flags are not properly applied when processing message-level 'raw' options. This flaw allows an authenticated attacker to provide malicious path or href properties within the email structure. By exploiting this, an attacker can coerce the server into performing server-side request forgery (SSRF) to interact with internal resources or to read arbitrary files from the filesystem. The contents of these files or the response from the internal requests are then exfiltrated to an attacker-controlled recipient via the outgoing email message. This vulnerability poses a significant risk to applications using Nodemailer to process user-supplied email content or templates, as it bypasses intended security sandbox restrictions.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows authenticated users to exfiltrate sensitive internal configuration files, credentials, or metadata via email. It also facilitates SSRF, enabling attackers to probe internal network services and sensitive APIs that are not exposed to the public internet, potentially leading to further compromise of the internal environment.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003eUpdate Nodemailer to version 9.0.1 or later immediately to ensure that 'disableFileAccess' and 'disableUrlAccess' flags are correctly enforced during message processing.\u003c/p\u003e\n","date_modified":"2026-08-31T11:59:00Z","date_published":"2026-08-31T11:17:45Z","id":"https://feed.craftedsignal.io/briefs/2026-08-nodemailer-ssrf-file-read/","summary":"Nodemailer versions before 9.0.1 fail to enforce security flags when processing message-level raw options, allowing authenticated attackers to perform SSRF and read arbitrary files.","title":"Nodemailer SSRF and Arbitrary File Read Vulnerability","url":"https://feed.craftedsignal.io/briefs/2026-08-nodemailer-ssrf-file-read/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:nodemailer:nodemailer:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}