GHSA-wfrj-qqc2-83cm
Dashboard / Vulnerabilities / GHSA-wfrj-qqc2-83cm
GHSA-wfrj-qqc2-83cm
Summary: Remote command injection when using sendmail email transport
Details: ### Impact Sites using the `sendmail` transport as part of their `mail` config are vulnerable to remote command injection due to a [vulnerability](https://github.com/advisories/GHSA-48ww-j4fc-435p) in the `nodemailer` dependency. Ghost defaults to the `direct` transport so this is only exploitable if the `sendmail` transport is explicitly used. ### Patches Fixed in 4.15.0, all sites should upgrade as soon as possible. ### Workarounds * Use an alternative email transport as described in the [docs](https://ghost.org/docs/config/#mail). ### For more information If you have any questions or comments about this advisory: * email us at [email protected]
References: https://github.com/TryGhost/Ghost/security/advisories/GHSA-wfrj-qqc2-83cm, https://github.com/TryGhost/Ghost/commit/93e4b2eafd18bc8e4c17924e0824e73617e7940c, https://github.com/TryGhost/Ghost, https://github.com/advisories/GHSA-48ww-j4fc-435p
Affected packages
Package
Name: ghost
Purl: pkg:npm/ghost
Affected ranges
Type: SEMVER
Events:
