SB2026093098 - External Control of File Name or Path in nodemailer
Published: September 30, 2026 Updated: September 30, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) External Control of File Name or Path (CVE-ID: CVE-2026-82659)
CWE-ID: CWE-73 - External Control of File Name or Path
CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to improper enforcement of file and URL access restrictions in the message-level raw option when processing untrusted raw message content. A remote user can supply raw content that references local paths or URLs and select a message recipient to disclose sensitive information.
Exploitation requires an application to enable file or URL access restrictions while allowing untrusted input to influence the raw field.
Remediation
Install update from vendor's website.