diff --git a/.changeset/smtp-injection-guard.md b/.changeset/smtp-injection-guard.md deleted file mode 100644 index 3974fc5..0000000 --- a/.changeset/smtp-injection-guard.md +++ /dev/null @@ -1,5 +0,0 @@ ---- -"@opencoredev/email-sdk": patch ---- - -Reject SMTP envelope addresses and header names that contain control characters, whitespace, or angle brackets before connecting. This closes an SMTP command/header injection vector where a crafted recipient address or header name could smuggle extra SMTP commands or headers into the session. diff --git a/packages/email-sdk/CHANGELOG.md b/packages/email-sdk/CHANGELOG.md index 062af95..1d15a2d 100644 --- a/packages/email-sdk/CHANGELOG.md +++ b/packages/email-sdk/CHANGELOG.md @@ -1,5 +1,11 @@ # @opencoredev/email-sdk +## 0.6.2 + +### Patch Changes + +- 9c8ff24: Reject SMTP envelope addresses and header names that contain control characters, whitespace, or angle brackets before connecting. This closes an SMTP command/header injection vector where a crafted recipient address or header name could smuggle extra SMTP commands or headers into the session. + ## 0.6.1 ### Patch Changes diff --git a/packages/email-sdk/package.json b/packages/email-sdk/package.json index 32130d3..cb834cd 100644 --- a/packages/email-sdk/package.json +++ b/packages/email-sdk/package.json @@ -1,6 +1,6 @@ { "name": "@opencoredev/email-sdk", - "version": "0.6.1", + "version": "0.6.2", "description": "A TypeScript email SDK for unified transactional sending.", "keywords": [ "bun",