nodemailer is an Easy as cake e-mail sending from your Node.js applications
Affected versions of this package are vulnerable to Command Injection. Use of crafted recipient email addresses may result in arbitrary command flag injection in sendmail transport for sending mails.
-email@example.com (-bi Initialize the alias database.) -firstname.lastname@example.org (The option -d0.1 prints the version of sendmail and the options it was compiled with.) -Dfilename@example.com (Debug output ffile)
nodemailer to version 6.4.16 or higher.