THREAT OPS › Threat News › [GHSA] GHSA-8m3c-c648-2xjj (medium) — Nodemailer: resolveContent() on a MailMessage bypasses disableFileAccess/disableUrlAccess when called with the legacy signature
[GHSA] GHSA-8m3c-c648-2xjj (medium) — Nodemailer: resolveContent() on a MailMessage bypasses disableFileAccess/disableUrlAccess when called with the legacy signature
GHSA-8m3c-c648-2xjj Severity: medium CVE: None
Nodemailer: resolveContent() on a MailMessage bypasses disableFileAccess/disableUrlAccess when called with the legacy signature
### Summary
Nodemailer's `disableFileAccess` / `disableUrlAccess` options are a security sandbox that lets an application forbid untrusted message content (`html`/`text`/attachment `path`/`href`) from reading local files o
Indicators of compromise
- efd6e29c10c6e0c25c57bd2f2a71302838235a4fsha1
- CVE-2026-82660cve
- CVE-2026-82659cve
- http://http-sink:8080/poc-ssrfurl
Original source: https://github.com/advisories/GHSA-8m3c-c648-2xjj