In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsUpgrade nodemailer to version 9.1.0 or higher.
nodemailer is an Easy as cake e-mail sending from your Node.js applications
Affected versions of this package are vulnerable to Interpretation Conflict via RFC 5322 comment mis-parsing in lib/addressparser/index.js. An attacker can make mail be delivered to an attacker-controlled domain by supplying a recipient such as user@good-corp.com(x)evil.com, which the parser glues into good-corp.comevil.com instead of treating the comment as folding whitespace. Applications that approve recipients by parsing or matching the domain separately can be tricked into sending mail to a domain they never intended to allow, exposing messages to the attacker-controlled recipient.