smtp-server@3.4.2

Vulnerabilities

1 via 1 paths

Dependencies

3

Source

npm

Find, fix and prevent vulnerabilities in your code.

Severity
  • 1
Status
  • 1
  • 0
  • 0

high severity

Command Injection

  • Vulnerable module: nodemailer
  • Introduced through: nodemailer@4.7.0

Detailed paths

  • Introduced through: smtp-server@3.4.2 nodemailer@4.7.0
    Remediation: Upgrade to smtp-server@3.8.0.

Overview

nodemailer is an Easy as cake e-mail sending from your Node.js applications

Affected versions of this package are vulnerable to Command Injection. Use of crafted recipient email addresses may result in arbitrary command flag injection in sendmail transport for sending mails.

PoC

-bi@example.com (-bi Initialize the alias database.)
-d0.1a@example.com (The option -d0.1 prints the version of sendmail and the options it was compiled with.)
-Dfilename@example.com (Debug output ffile)

Remediation

Upgrade nodemailer to version 6.4.16 or higher.

References