Description
The current upstream main branch at commit 7e0206d was reviewed, and the fix-first patch set was rebased on 2026-05-18.
Recommendation
Update the @agenticmail/core package to the latest compatible version. Followings are version details:
- Affected version(s): <= 0.9.9
- Patched version(s): 0.9.10
References
- GHSA-wjjv-3mj2-39hf
- CVE-2026-47255
- CWE-20
- CWE-284
- CWE-319
- CWE-798
- CWE-89
- CAPEC-310
- OWASP 2021-A1
- OWASP 2021-A2
- OWASP 2021-A3
- OWASP 2021-A6
- OWASP 2021-A7
Related Issues
- AgenticMail: Unauthenticated inbound mail triggers bypassPermissions resume of the operator's Claude Code session (bridg - CVE-2026-57495
- Payload has Insufficient Filename Validation in Client-Upload Signed-URL Endpoints - @payloadcms/storage-gcs - CVE-2026-34750
- Payload has Insufficient Filename Validation in Client-Upload Signed-URL Endpoints - @payloadcms/storage-r2 - CVE-2026-34750
- StudioCMS: REST API Missing Rank Check Allows Admin to Create Peer Admin Accounts - CVE-2026-32106
You might also like:
- Tags:
- npm
- @agenticmail/core
Anything's wrong? Let us know Last updated on May 29, 2026


