PT-2026-99370 · Npm · Nodemailer
CVSS v4.0
6.9
Medium
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
Nodemailer versions 9.1.0 through 10.0.8
Description
The address parser in
src/addressparser mishandles email addresses where the local-part is a quoted string followed by RFC 5322 comments. This allows trailing comment-separated domain atoms to be retained in the normalized address. For instance, an input like "user"@example.com(x)evil.com may be parsed as 'user@example.com evil.com', introducing attacker-controlled domain text. This value is then used in the message envelope envelope.to within src/mime-node without strict recipient validation, potentially allowing malformed or ambiguous recipient addresses to be accepted in the SMTP envelope.Recommendations
Update to version 10.0.9.
Exploit
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Nodemailer