CVE-2020-7769

HIGH

nodemailer <6.4.16 - Command Injection

Title source: llm
STIX 2.1

Description

This affects the package nodemailer before 6.4.16. Use of crafted recipient email addresses may result in arbitrary command flag injection in sendmail transport for sending mails.

References (4)

Core 4

Scores

CVSS v3 8.6
EPSS 0.0232
EPSS Percentile 81.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H

Details

CWE
CWE-88
Status published
Products (2)
nodemailer/nodemailer < 6.4.16
npm/nodemailer 0 - 6.4.16npm
Published Nov 12, 2020
Tracked Since Feb 18, 2026