Skip to content

chore: upgrade nodemailer to ^10.0.2 to address GHSA-6vj9-mwq6-2f5v, GHSA-8vvx-rff5-p5rq - #1703

Open
claude[bot] wants to merge 2 commits into
mainfrom
cursor/cve/nodemailer-2026-09
Open

claude[bot] wants to merge 2 commits into
mainfrom
cursor/cve/nodemailer-2026-09

Conversation

@claude

@claude claude Bot commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

Fixes SOU-2390
Fixes SOU-2391

Summary

Upgrades the direct @sourcebot/web dependency nodemailer from ^9.0.1 (locked 9.1.1) to ^10.0.2 (locked 10.0.13). No 9.x release contains the fixes, so a lockfile refresh is not enough.

  • GHSA-6vj9-mwq6-2f5v: the process-global DNS cache reused the TLS servername across transports, which could disclose SMTP credentials across tenants (fixed in 10.0.2).
  • GHSA-8vvx-rff5-p5rq: nested structured recipient arrays bypassed the parser depth limit and caused stack exhaustion (fixed in 10.0.2).

Upgrade notes

  • The only breaking change in nodemailer 10.0.0 is requiring Node.js 20 or newer. Sourcebot already requires Node.js 24.
  • nodemailer 10 ships its own TypeScript declarations, where SentMessageInfo.pending is optional. The four result.rejected.concat(result.pending) call sites (auth.ts, accountRequests.ts x2, invites.ts) now use result.pending ?? []. Runtime behaviour doesn't change, because .filter(Boolean) already dropped an undefined entry.

Note: the conventional cursor/cve/nodemailer branch name is still held by a stale branch from merged PR #1642, so this PR uses cursor/cve/nodemailer-2026-09.

Verification

  • yarn why nodemailer: the only instance resolves to nodemailer@npm:10.0.13.
  • yarn workspace @sourcebot/web tsc --noEmit: no errors besides the pre-existing @/public/* image/SVG module errors, which come from the local checkout not having a generated next-env.d.ts and don't involve nodemailer.
  • yarn workspace @sourcebot/web lint: clean.
  • yarn workspace @sourcebot/web test: 1506 passed.
  • yarn workspace @sourcebot/web build: succeeds.

🤖 Generated with Claude Code


Note

Medium Risk
Touches SMTP paths used for login and membership email; the dependency bump fixes credential-leak and DoS CVEs but still warrants verifying outbound mail in staging.

Overview
Upgrades @sourcebot/web's direct nodemailer dependency from ^9.0.1 to ^10.0.2 (lockfile resolves to 10.0.13), addressing security advisories that are only fixed in 10.x—not via a lockfile-only bump on 9.x.

After send, failure detection in magic-link login (auth.ts), join-request notifications, approval emails, and org invites now treats SentMessageInfo.pending as optional with result.pending ?? [], matching nodemailer 10's bundled types without changing runtime behavior when pending is absent.

Reviewed by Cursor Bugbot for commit 3a2081c. Bugbot is set up for automated code reviews on this repo. Configure here.

github-actions Bot and others added 2 commits September 30, 2026 14:36
…HSA-8vvx-rff5-p5rq

nodemailer 10 ships its own type declarations, where SentMessageInfo.pending
is optional. Default it to an empty array before concatenating.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@coderabbitai

coderabbitai Bot commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Advanced

Run ID: 4bf985e7-6a69-4937-9387-c8d7b680747e

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.


Comment @coderabbitai help to get the list of available commands.

@github-actions

Copy link
Copy Markdown
Contributor

License Audit

❌ Audit failed to produce results. Check the workflow logs for details.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants