SMTP Command Injection Vulnerability in Nodemailer by Nodemailer
CVE-2026-82853
6.9MEDIUM
What is CVE-2026-82853?
Nodemailer versions prior to 8.0.5 are susceptible to an SMTP command injection vulnerability due to the improper handling of transport name options in EHLO/HELO commands. This flaw enables attackers to inject arbitrary SMTP commands by exploiting unvalidated carriage return and line feed characters. As a result, malicious actors can execute email spoofing attacks and manipulate email communications, posing significant risks to users and organizations relying on secure email services.
Affected Version(s)
nodemailer 0 < 8.0.5
nodemailer 8.0.5
