PT-2026-99370 · Npm · Nodemailer

·

CVE-2026-100699

·

Published

2026-09-26

·

Updated

2026-09-29

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Nodemailer versions 9.1.0 through 10.0.8
Description The address parser in src/addressparser mishandles email addresses where the local-part is a quoted string followed by RFC 5322 comments. This allows trailing comment-separated domain atoms to be retained in the normalized address. For instance, an input like "user"@example.com(x)evil.com may be parsed as 'user@example.com evil.com', introducing attacker-controlled domain text. This value is then used in the message envelope envelope.to within src/mime-node without strict recipient validation, potentially allowing malformed or ambiguous recipient addresses to be accepted in the SMTP envelope.
Recommendations Update to version 10.0.9.

Exploit

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-100699
GHSA-G57G-F23G-4646

Affected Products

Nodemailer