Intel

AIKIDO-2026-306294

nodemailer is vulnerable to Improper Input Validation

Improper Input ValidationGHSA-g73g-hqqh-jr95 Published 2 days ago

53

Medium Risk

This Affects:

JSnodemailer
3.0.0 - 10.0.12
Fixed in 10.0.13
Are you affected? Scan for Free

TL;DR

Nodemailer's address parser strips RFC 5322 comments from a quoted local part or a bare addr-spec, but not when the address appears inside angle brackets after a display name, the most common way to write a recipient. A comment placed between the local part and domain of an angle bracket address passes through unstripped and reaches envelope.to and the To header. A conformant SMTP server rejects the resulting malformed RCPT TO command, and other mail systems may handle the parenthesized text differently. The fix applies the same comment handling to the angle bracket address path.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and you accept recipient or sender addresses containing RFC 5322 comments from an untrusted or externally supplied source.

Background info

nodemailer is vulnerable to Improper Input Validation in versions 3.0.0 - 10.0.12.

How to fix this

Upgrade the nodemailer library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform