Easy as cake e-mail sending from your Node.js applications
91%
Total Score
62
100
100
95
100
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-10941 New nodemailer is vulnerable to Missing Authorization in versions 0.0.0 - 8.0.8. | 0.0.0 - 8.0.8 | Medium |
AIKIDO-2026-10942 New nodemailer is vulnerable to CRLF Injection in versions 0.0.0 - 8.0.8. | 0.0.0 - 8.0.8 | Medium |
CVE-2025-14874 nodemailer is vulnerable to Improper Check or Handling of Exceptional Conditions in versions 0.0.0 - 7.0.10. | 0.0.0 - 7.0.10 | High |
CVE-2025-13033 nodemailer is vulnerable to Improper Input Validation in versions 0.0.0 - 7.0.7. | 0.0.0 - 7.0.7 | Medium |
AIKIDO-2024-10079 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. nodemailer is vulnerable to Regular Expression Denial of Service (ReDoS) in versions 3.0.0 - 6.9.8. | 3.0.0 - 6.9.8 | Medium |
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant