Please take a look at, https://github.com/mailgun/mailgun.js/issues/126 It appears that mailgun-js introduces a security vulnerability