Provides email sending and receiving via SMTP/IMAP/POP3, supporting major email providers and dynamic authentication for AI assistant integration.
Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find.
Install from
M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.
Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.
Nodemailer: Message-level raw option bypasses disableFileAccess/disableUrlAccess, enabling arbitrary file read and full-response SSRF in the delivered message
Nodemailer: CRLF injection in Nodemailer List-* header comments allows arbitrary message header injection
Nodemailer has SMTP command injection due to unsanitized `envelope.size` parameter
Nodemailer: Improper TLS Certificate Validation in OAuth2 Token Fetch Enables Credential Interception
Nodemailer Vulnerable to SMTP Command Injection via CRLF in Transport name Option (EHLO/HELO)
process.env. You'll be asked to provide them before it can run.EMAIL_PASS— "": "your-app-password",EMAIL_PROVIDER— "": "gmail"EMAIL_USER— "": "your-email@gmail.com",IMAP_HOSTIMAP_PASSIMAP_PORTIMAP_SECUREIMAP_USERMCP_STDIOPOP3_HOSTPOP3_PASSPOP3_PORTPOP3_SECUREPOP3_USERPORTSMTP_HOST— your-smtp-server.comSMTP_PASS— your-passwordSMTP_PORTSMTP_SECURESMTP_USER— your-email@example.com[](https://m8ven.ai/mcp/1018053166-sse-email-mcp-server-wsp1p1)