CVE-2026-82854 | Nodemailer up to 8.0.3 Envelope Size sendMail envelope.size command injection
A vulnerability classified as critical was found in Nodemailer up to 8.0.3. Affected is the function sendMail of the component Envelope Size. Executing a manipulation of the argument envelope.size can lead to command injection.
The identification of this vulnerability is CVE-2026-82854. The attack may be launched remotely. There is no exploit available.
Upgrading the affected component is advised.VulDB Recent EntriesRead More