High severity8.6NVD Advisory· Published Nov 12, 2020· Updated Jun 17, 2026
CVE-2020-7769
CVE-2020-7769
Description
This affects the package nodemailer before 6.4.16. Use of crafted recipient email addresses may result in arbitrary command flag injection in sendmail transport for sending mails.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
nodemailernpm | < 6.4.16 | 6.4.16 |
Affected products
2Patches
Vulnerability mechanics
References
8- github.com/nodemailer/nodemailer/commit/ba31c64c910d884579875c52d57ac45acc47aa54nvdPatchThird Party AdvisoryWEB
- snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1039742nvdExploitPatchThird Party AdvisoryWEB
- snyk.io/vuln/SNYK-JS-NODEMAILER-1038834nvdExploitPatchThird Party AdvisoryWEB
- github.com/advisories/GHSA-48ww-j4fc-435pghsaADVISORY
- github.com/nodemailer/nodemailer/blob/33b62e2ea6bc9215c99a9bb4bfba94e2fb27ebd0/lib/sendmail-transport/index.js%23L75nvdBroken LinkThird Party AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2020-7769ghsaADVISORY
- github.com/nodemailer/nodemailer/blob/33b62e2ea6bc9215c99a9bb4bfba94e2fb27ebd0/lib/sendmail-transport/index.jsghsaWEB
- www.npmjs.com/package/nodemailerghsaWEB
News mentions
0No linked articles in our index yet.