Stats Digest Feeds
โ† Back to all CVEs

CVE-2026-82854

CRITICAL NVD
CVSS Score 9.8
Severity CRITICAL
Published Aug 31, 2026
Vendor unknown

Description

Nodemailer before 8.0.4 is vulnerable to SMTP command injection through the unsanitized envelope.size parameter. When an application passes a custom envelope object with a size property containing CRLF characters to sendMail(), the value is concatenated into the SMTP MAIL FROM command (as SIZE=...) without sanitization, allowing injection of arbitrary SMTP commands such as RCPT TO to silently add attacker-controlled recipients. Exploitation requires the application to expose the envelope size to attacker-controlled input, as Nodemailer does not include size in the default auto-constructed envelope.

References