Server-Side Request Forgery (SSRF) in nodemailer - CVE-2026-92595
Published: September 30, 2026
Vulnerability details
The vulnerability allows a remote user to disclose arbitrary local files and perform server-side request forgery.
The vulnerability exists due to improper access control in the MailMessage.resolveContent() public API when resolving attacker-influenced message content through the legacy signature. A remote user can supply message content that references local file paths or internal URLs to disclose arbitrary local files and perform server-side request forgery.
The issue is reachable when disableFileAccess or disableUrlAccess is enabled and application code or a plugin invokes the documented legacy API without an options argument.
Affected software
IBM App Connect Enterprise
How to mitigate CVE-2026-92595
IBM App Connect Enterprise - update to 13.0.9.0