notifme / notifme-sdk

A Node.js library to send all kinds of transactional notifications.
https://notifme.github.io/www/
MIT License
1.94k stars 150 forks source link

nodemailer Command Injection vulnerability #85

Closed pmaterniak closed 6 months ago

pmaterniak commented 3 years ago

This package has a dependency towards nodemailer@6.4.12 which has an upstream vulnerability towards nodemailer: https://www.npmjs.com/advisories/1708

The vulnerability has been fixed upstream by nodemailer@6.4.16 so it could be desired to release a new version of this package bumping that dependency.

BDav24 commented 6 months ago

nodemailer was upgraded to 6.9.8 in https://github.com/notifme/notifme-sdk/releases/tag/v1.12.0