nodemailer before 9.0.1 fails to apply disableFileAccess and disableUrlAccess flags to message-level raw option, allowing authenticated attackers to read arbitrary files or perform server-side request forgery by supplying path or href properties. Attackers can exploit this by crafting raw messages with file paths or URLs that bypass the intended sandbox, with fetched content delivered in the outgoing message to attacker-controlled recipients.
Casky was already ahead
This CVE exploits attack patterns that Casky's 0matched skills already investigate — long before this vulnerability was disclosed. Claude's reasoning model maps these techniques to MITRE ATT&CK, so practitioners who ran these skills have already seen the threat behaviour in their findings.
CVE-2026-82659 represents a sandbox escape vulnerability in nodemailer versions prior to 9.0.1, where the disableFileAccess and disableUrlAccess security flags fail to apply constraints to message-level raw options. This allows authenticated attackers to embed arbitrary file paths or URLs directly within raw message content, bypassing intended protections and enabling two critical attack vectors: unauthorized file disclosure from the mail server and server-side request forgery (SSRF) attacks. The vulnerability is particularly dangerous because it affects authenticated users who may have legitimate access to the mailing service, making detection harder while expanding the attack surface significantly. Any organization using nodemailer for email functionality—especially in multi-tenant environments, SaaS platforms, or applications that accept user-crafted email content—faces risk of confidential data exfiltration and internal network reconnaissance.
While this CVE does not currently map to specific MITRE ATT&CK techniques in the initial assessment, Casky's skill-based detection system would identify the underlying attack patterns through behavioral analysis of email processing workflows. Practitioners using Casky would observe suspicious indicators such as: raw message content containing file:// scheme references or internal URL patterns inconsistent with normal email operations; email metadata showing mismatches between declared message content and actual fetched resources; and outbound SSRF attempts originating from mail processing services. By analyzing the interaction between message construction, file access patterns, and network communication—leveraging Claude's extended reasoning across the 754 mapped security skills—Casky would flag anomalous email generation activities that exploit this sandbox bypass, enabling defenders to detect exploitation attempts even without explicit CVE signatures.
Composite risk scoring from EPSS, CISA KEV, Shodan, and GreyNoise — 21 security APIs correlated into a single Casky Risk Score. Coming in Casky Pro. Join early access →
Casky has 0 skills that investigate the attack patterns behind CVE-2026-82659. Run one and get CVSS-scored findings in 3 minutes.
Run the skill that detects this →© 2026 Casky.AI, Inc. · AI Security Investigation