Executive brief
Nodemailer, a widely-used Node.js email-sending library, contains a security bypass in its message composition feature. When applications configure access restrictions to prevent reading local files or making remote requests, the message-level "raw" option ignores these restrictions, allowing attackers to read sensitive server files or make forged requests to internal services. This affects all email transports (SMTP, SES, sendmail, stream) and can expose confidential data sent to recipients.
Technical details
The vulnerability is a security control bypass (CWE-73, CWE-918) in Nodemailer's MailComposer.compile() function. When processing a message with the raw option, the code creates a MIME node without passing disableFileAccess or disableUrlAccess flags that are otherwise enforced for other content types (attachments, alternatives, etc.). Consequently, raw: { path: '/etc/passwd' } or raw: { href: 'http://169.254.169.254/...' } constructs read local files or fetch URLs regardless of the flags configured on the transporter or message. An authenticated or untrusted-input attacker can thus achieve arbitrary local-file disclosure and server-side request forgery (SSRF), with the resulting content embedded in the delivered RFC822 message across all transports. Patch is available in version 9.0.1.
Affected products
- Nodemailer Nodemailer <= 9.0.0
Timeline
- 2026-06-17: disclosed
- 2026-06-17: patched: Fixed in version 9.0.1