notifme / notifme-sdk

A Node.js library to send all kinds of transactional notifications.

Home Page:https://notifme.github.io/www/

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

nodemailer Command Injection vulnerability

pmaterniak opened this issue · comments

This package has a dependency towards nodemailer@6.4.12 which has an upstream vulnerability towards nodemailer: https://www.npmjs.com/advisories/1708

The vulnerability has been fixed upstream by nodemailer@6.4.16 so it could be desired to release a new version of this package bumping that dependency.