HIGHVulnerability

CVE-2026-82659

nodemailer before 9.0.1 fails to apply disableFileAccess and disableUrlAccess flags to message-level raw option, allowing authenticated attackers to read arbitrary files or perform server-side request forgery by supplying path or href properties. Attackers can exploit this by crafting raw messages with file paths or URLs that bypass the intended sandbox, with fetched content delivered in the outgoing message to attacker-controlled recipients.

Properties

severity
HIGH
score
7.1
epss_score
0.00254
cve_id
CVE-2026-82659
signal_observed_at
2026-09-15T21:12:48+00:00
vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
published_at
2026-08-31T09:17:03.633
last_modified
2026-09-10T15:48:28.757
epss_percentile
0.1701

Related Entities (3)

ENRICHED_BY (1)

[Source]FIRST EPSS

HAS_WEAKNESS (1)

[Weakness]External Control of File Name or Path

DESCRIBED_BY (1)

[Source]NVD

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-82659 — Ninja Signal Threat Intelligence | Ninja Signal