All vulnerabilities

GHSA-P6GQ-J5CR-W38F

npm · nodemailer

Summary

Nodemailer: Message-level raw option bypasses disableFileAccess/disableUrlAccess, enabling arbitrary file read and full-response SSRF in the delivered message

References