External Control of File Name or Path in nodemailer - CVE-2026-82659

 

External Control of File Name or Path in nodemailer - CVE-2026-82659

Published: September 30, 2026


Vulnerability identifier: #VU153009
CSH Severity: Low
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-82659
CWE-ID: CWE-73
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to disclose sensitive information.

The vulnerability exists due to improper enforcement of file and URL access restrictions in the message-level raw option when processing untrusted raw message content. A remote user can supply raw content that references local paths or URLs and select a message recipient to disclose sensitive information.

Exploitation requires an application to enable file or URL access restrictions while allowing untrusted input to influence the raw field.


Affected software

nodemailer

How to mitigate CVE-2026-82659

Install security update from vendor's website.

nodemailer - update to 9.0.1

External References

Related Security Bulletins