GHSA-h3hj-cmcx-xc66: High severity npm/nodemailer vulnerability

Published Aug 31, 2026
·
Updated

Duplicate Advisory

This advisory has been withdrawn because it is a duplicate of GHSA-p6gq-j5cr-w38f. This link is maintained to preserve external references.

Original Description nodemailer before 9.0.1 fails to apply disableFileAccess and disableUrlAccess flags to message-level raw option, allowing authenticated attackers to read arbitrary files or perform server-side request forgery by supplying path or href properties. Attackers can exploit this by crafting raw messages with file paths or URLs that bypass the intended sandbox, with fetched content delivered in the outgoing message to attacker-controlled recipients.

Affected Software

1 affected component
npm/nodemailer<=9.0.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade nodemailer to a version that resolves this vulnerability.

    Fixed in 9.0.1
  2. Configuration

    Ensure message-level raw option flags disableFileAccess and disableUrlAccess are correctly applied to raw options so file path (path) and URL (href) access is disabled (affected in nodemailer before 9.0.1).

    nodemailer disableFileAccess / disableUrlAccess (message-level raw option) = true

Event History

Aug 31, 2026
Advisory Published
via GitHub·09:30 AM
Data Sourced
via GitHub·09:30 AM
DescriptionSeverityWeaknessAffected Software
Sep 2, 2026
Withdrawn
via GitHub·02:47 PM

Frequently Asked Questions

1

Who can exploit this issue?

An attacker needs authenticated access sufficient to supply a message-level raw option to Nodemailer. Exploitation also requires the ability to set path or href properties in the crafted raw message.

2

What is exposed if exploitation succeeds?

An attacker can read arbitrary files or trigger server-side requests through the affected Nodemailer process. Content obtained from a file or URL can be sent in an outgoing message to recipients controlled by the attacker.

3

Are installations with file and URL access disabled protected?

Not for message-level raw input in affected versions. The issue is that disableFileAccess and disableUrlAccess are not applied to that raw option, allowing the intended sandbox restrictions to be bypassed.

4

What versions are affected?

The original advisory identifies Nodemailer versions before 9.0.1 as affected. This advisory has been withdrawn as a duplicate of GHSA-p6gq-j5cr-w38f.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203