Description
Nodemailer (npm package `nodemailer`) versions 9.1.0 and earlier do not honor the `disableFileAccess` and `disableUrlAccess` sandbox options when message content is resolved through the public plugin API `MailMessage.resolveContent()` using the documented legacy three-argument signature `resolveContent(data, key, callback)`. Because `shared.resolveContent()` normalizes the missing `options` argument to an empty object, the message-level flags copied into `mail.data` by the MailMessage constructor are discarded, and `resolveContentValue()` skips both access-control checks, reaching `nmfetch(url)` or `fs.createReadStream(path)`. As a result, plugin or application code that resolves untrusted message content (html, text, attachment `path` or `href`) via this API can be induced to read arbitrary local files or issue outbound HTTP(S) requests (server-side request forgery), bypassing the sandbox the application enabled. The internal paths used by `transporter.sendMail()` (`resolveAll()`, `_convertDataImages()`, and the MIME streaming path) are not affected. Fixed in version 9.1.1.
Published: 2026-09-16
Score: 6 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Arbitrary Local File Read & SSRF via sandbox bypass
Action: Patch to 9.1.1
AI Analysis

Impact

Nodemailer versions prior to 9.1.1 ignore the sandbox directives that block file and URL access when message content is resolved through the legacy three‑argument form of MailMessage.resolveContent. The internal implementation substitutes an empty options object, so the per‑message flags disableFileAccess and disableUrlAccess are lost. As a result, code that resolves untrusted content can invoke the file system or perform outbound HTTP(S) calls, allowing local file disclosure and server‑side request forgery. This flaw does not affect the internal paths used by transporter.sendMail, but it enables an attacker who controls the plugin or message content to access arbitrary files or reach internal network resources.

Affected Systems

The vulnerability affects the Node.js NPM package nodemailer, product nodemailer, in all released versions up to and including 9.1.0. The fix was introduced in version 9.1.1 and later releases contain the enforcement of sandbox options.

Risk and Exploitability

The CVSS score of 6 indicates a moderate severity, with no exploitation probability reported and an EPSS score below 1%. The vulnerability is not listed in the CISA KEV catalog. Exploitation can occur when an application or plugin calls resolveContent using the legacy signature on content that may include untrusted html, text, attachment paths or URLs. Because the bypass removes access controls, an attacker with the ability to choose content can read local files or cause the server to fetch arbitrary URLs, potentially leaking sensitive data or facilitating further network attacks. The attack vector is local to the Node.js process and does not require external network interaction for the initial exploit.

Generated by OpenCVE AI on September 23, 2026 at 01:44 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade nodemailer to version 9.1.1 or newer, which correctly applies disableFileAccess and disableUrlAccess settings.
  • Rewrite any plugin or application code that uses MailMessage.resolveContent to call the two‑argument form or the form that accepts an options object, ensuring that the sandbox options are preserved.
  • If rewriting the call is infeasible, remove or isolate the plugin code that processes untrusted content, or add custom validation to refuse file paths and enforce a whitelist of outbound URLs.

Generated by OpenCVE AI on September 23, 2026 at 01:44 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 23 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-918
References
Metrics threat_severity

None

threat_severity

Moderate


Sat, 19 Sep 2026 02:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Description Nodemailer (npm package `nodemailer`) versions 9.1.0 and earlier do not honor the `disableFileAccess` and `disableUrlAccess` sandbox options when message content is resolved through the public plugin API `MailMessage.resolveContent()` using the documented legacy three-argument signature `resolveContent(data, key, callback)`. Because `shared.resolveContent()` normalizes the missing `options` argument to an empty object, the message-level flags copied into `mail.data` by the MailMessage constructor are discarded, and `resolveContentValue()` skips both access-control checks, reaching `nmfetch(url)` or `fs.createReadStream(path)`. As a result, plugin or application code that resolves untrusted message content (html, text, attachment `path` or `href`) via this API can be induced to read arbitrary local files or issue outbound HTTP(S) requests (server-side request forgery), bypassing the sandbox the application enabled. The internal paths used by `transporter.sendMail()` (`resolveAll()`, `_convertDataImages()`, and the MIME streaming path) are not affected. Fixed in version 9.1.1.
Title Nodemailer before 9.1.1 Security Sandbox Bypass via resolveContent
First Time appeared Nodemailer
Nodemailer nodemailer
Weaknesses CWE-73
CPEs cpe:2.3:a:nodemailer:nodemailer:*:*:*:*:*:*:*:*
Vendors & Products Nodemailer
Nodemailer nodemailer
References
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:L/A:N'}

cvssV4_0

{'score': 6, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Nodemailer Nodemailer
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-19T02:05:35.346Z

Reserved: 2026-09-16T13:47:49.170Z

Link: CVE-2026-92595

cve-icon Vulnrichment

Updated: 2026-09-19T02:05:28.270Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-16T22:18:30.417

Modified: 2026-09-22T20:25:55.870

Link: CVE-2026-92595

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-16T21:47:00Z

Links: CVE-2026-92595 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-23T01:45:19Z

Weaknesses
  • CWE-73

    External Control of File Name or Path

  • CWE-918

    Server-Side Request Forgery (SSRF)