ZeroHour

Search: “nodemailer”

4 stories

[webapps] Nodemailer 9.0.0 - File Read/ SSRF

A public proof-of-concept demonstrates arbitrary file read and SSRF in Nodemailer 9.0.0.

Exploit-DB entry 52654 contains a webapps proof-of-concept for Nodemailer 9.0.0 demonstrating both arbitrary file read and server-side request forgery. Nodemailer is a widely used Node.js email-sending library, so affected deployments could expose local files or internal services. The listing does not include a CVE identifier or evidence of in-the-wild exploitation.

Exploit-DB · 28d agoExploit / PoC