Executive brief
Nodemailer is a popular Node.js library for sending emails via various transports, including the Unix sendmail binary. A flaw in how it constructs sendmail command arguments allows attackers to inject arbitrary command-line flags by crafting malicious recipient email addresses. An attacker who can control email recipient addresses sent to a vulnerable application could execute arbitrary sendmail commands, potentially enabling information disclosure, service disruption, or system compromise.
Technical details
This vulnerability exists in nodemailer's sendmail transport implementation, which passes recipient email addresses directly to the sendmail binary without proper sanitization or escaping. An attacker can craft recipient addresses containing special characters or flags (e.g., "-bi@example.com", "-d0.1a@example.com") that are interpreted as sendmail command-line options rather than email addresses. The vulnerability is classified as CWE-88 (argument injection) and affects all versions before 6.4.16. The attack requires only that the application accept attacker-controlled recipient addresses and use the sendmail transport; no authentication or user interaction is needed. A successful exploit can result in arbitrary sendmail flag injection, potentially leading to information disclosure (via debug output), service disruption, or other sendmail-specific impacts depending on available flags and system configuration. The issue was patched in version 6.4.16.
Affected products
- nodemailer nodemailer before 6.4.16
Timeline
- 2020-11-11: disclosed
- 2020-11-12: patched: Version 6.4.16 released with fix
- 2021-05-10: advisory: GitHub Security Advisory GHSA-48ww-j4fc-435p published
References
- https://github.com/nodemailer/nodemailer/commit/ba31c64c910d884579875c52d57ac45acc47aa54
- https://github.com/nodemailer/nodemailer/blob/33b62e2ea6bc9215c99a9bb4bfba94e2fb27ebd0/lib/sendmail-transport/index.js
- https://github.com/nodemailer/nodemailer/blob/33b62e2ea6bc9215c99a9bb4bfba94e2fb27ebd0/lib/sendmail-transport/index.js%23L75
- https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1039742
- https://snyk.io/vuln/SNYK-JS-NODEMAILER-1038834
- https://www.npmjs.com/package/nodemailer