External Control of File Name or Path in nodemailer - CVE-2026-82659
Published: September 30, 2026
Vulnerability details
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to improper enforcement of file and URL access restrictions in the message-level raw option when processing untrusted raw message content. A remote user can supply raw content that references local paths or URLs and select a message recipient to disclose sensitive information.
Exploitation requires an application to enable file or URL access restrictions while allowing untrusted input to influence the raw field.