SB2026093098 - External Control of File Name or Path in nodemailer



SB2026093098 - External Control of File Name or Path in nodemailer

Published: September 30, 2026 Updated: September 30, 2026

Security Bulletin ID SB2026093098
CSH Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) External Control of File Name or Path (CVE-ID: CVE-2026-82659)

CWE-ID: CWE-73 - External Control of File Name or Path

CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to disclose sensitive information.

The vulnerability exists due to improper enforcement of file and URL access restrictions in the message-level raw option when processing untrusted raw message content. A remote user can supply raw content that references local paths or URLs and select a message recipient to disclose sensitive information.

Exploitation requires an application to enable file or URL access restrictions while allowing untrusted input to influence the raw field.


Remediation

Install update from vendor's website.