[webapps] Nodemailer 9.0.0 - File Read/ SSRF
A public proof-of-concept demonstrates arbitrary file read and SSRF in Nodemailer 9.0.0.
Exploit-DB entry 52654 contains a webapps proof-of-concept for Nodemailer 9.0.0 demonstrating both arbitrary file read and server-side request forgery. Nodemailer is a widely used Node.js email-sending library, so affected deployments could expose local files or internal services. The listing does not include a CVE identifier or evidence of in-the-wild exploitation.
35