nodemailer is vulnerable to Improper Input Validation
53
Medium Risk
Nodemailer's address parser strips RFC 5322 comments from a quoted local part or a bare addr-spec, but not when the address appears inside angle brackets after a display name, the most common way to write a recipient. A comment placed between the local part and domain of an angle bracket address passes through unstripped and reaches envelope.to and the To header. A conformant SMTP server rejects the resulting malformed RCPT TO command, and other mail systems may handle the parenthesized text differently. The fix applies the same comment handling to the angle bracket address path.
You are affected if you are using a version that falls within the vulnerable range and you accept recipient or sender addresses containing RFC 5322 comments from an untrusted or externally supplied source.
nodemailer is vulnerable to Improper Input Validation in versions 3.0.0 - 10.0.12.
Upgrade the nodemailer library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.