Description
The current upstream main branch at commit 7e0206d was reviewed, and the fix-first patch set was rebased on 2026-05-18.
Recommendation
Update the @agenticmail/core package to the latest compatible version. Followings are version details:
- Affected version(s): <= 0.9.9
- Patched version(s): 0.9.10
References
Could your website be exposed too?
SmartScanner can check your website for AgenticMail API/storage and outbound relay hardening fixes and gives you actionable findings to investigate.
Start a free scanRelated Issues
- AgenticMail: Unauthenticated inbound mail triggers bypassPermissions resume of the operator's Claude Code session (bridg - CVE-2026-57495
- Payload has Insufficient Filename Validation in Client-Upload Signed-URL Endpoints - @payloadcms/storage-gcs - CVE-2026-34750
- Payload has Insufficient Filename Validation in Client-Upload Signed-URL Endpoints - @payloadcms/storage-r2 - CVE-2026-34750
- StudioCMS: REST API Missing Rank Check Allows Admin to Create Peer Admin Accounts - CVE-2026-32106
You might also like:
See something that needs correcting? Let us knowUpdated May 29, 2026


