WhisperX tag archive

#email

This page collects WhisperX intelligence signals tagged #email. It is designed for humans, search engines, and AI agents: each item links to a canonical source-backed record with sector, source, timestamp, credibility, and exportable structured data.

Latest Signals (5)

The Lab · 2026-03-30 12:27:16 · GitHub Issues

1. Nodemailer v8.0.4 Patches Critical SMTP Command Injection Vulnerability (GHSA-c7w3-x93f-qmm8)

A critical security flaw in the widely-used Nodemailer library allowed attackers to silently hijack email delivery by injecting arbitrary SMTP commands. The vulnerability, tracked as GHSA-c7w3-x93f-qmm8, was present when a custom `envelope` object with a `size` property was passed to the `sendMail()` function. If this ...

The Lab · 2026-04-16 20:22:54 · GitHub Issues

2. Path Traversal Vulnerability in Email Parser Exposes File System to Malicious Attachments

A critical path traversal vulnerability has been identified in the `parse_body()` function of an email parsing library. The flaw allows a malicious actor to embed directory traversal sequences (e.g., `../../../etc/passwd`) within the `Content-Disposition` header of an email attachment. The parser accepts the raw, unsan...

The Lab · 2026-04-18 03:22:35 · GitHub Issues

4. MailKit Security Flaw Exposes Email Clients to STARTTLS Downgrade Attacks

A critical vulnerability in the widely-used MailKit library allows attackers to intercept and downgrade email authentication, potentially exposing sensitive credentials. The flaw, tracked as GHSA-9j88-vvj5-vhgr, is a STARTTLS Response Injection vulnerability. It enables a Man-in-the-Middle (MitM) attacker to inject arb...

The Lab · 2026-04-18 03:22:36 · GitHub Issues

5. MailKit Security Flaw Exposes Email Clients to STARTTLS Injection, Downgrade Attacks

A critical vulnerability in the widely-used MailKit library allows attackers to inject malicious commands and force weaker authentication, compromising the security of countless email clients and applications. The flaw, tracked as GHSA-9j88-vvj5-vhgr, is a STARTTLS Response Injection vulnerability that enables a Man-in...