VDB
KO
MEDIUM 6.3

GHSA-hwqf-gcqm-7353

Header injection in nodemailer

Details

The package nodemailer before 6.6.1 are vulnerable to HTTP Header Injection if unsanitized user input that may contain newlines and carriage returns is passed into an address object.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm / nodemailer
Introduced in: 0 Fixed in: 6.6.1
Fix npm install nodemailer@6.6.1

References