CVE-2020-7769

HIGH

nodemailer <6.4.16 - Command Injection

Title source: llm

Description

This affects the package nodemailer before 6.4.16. Use of crafted recipient email addresses may result in arbitrary command flag injection in sendmail transport for sending mails.

Scores

CVSS v3 8.6
EPSS 0.0051
EPSS Percentile 66.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H

Classification

CWE
CWE-88
Status published

Affected Products (2)

nodemailer/nodemailer < 6.4.16
npm/nodemailer < 6.4.16npm

Timeline

Published Nov 12, 2020
Tracked Since Feb 18, 2026