This affects the package nodemailer before 6.4.16. Use of crafted recipient email addresses may result in arbitrary command flag injection in sendmail transport for sending mails.
| Software | From | Fixed in |
|---|---|---|
| nodemailer / nodemailer | - | 6.4.16 |
nodemailer
|
- | 6.4.16 |