Description
Two inbound-mail handlers act on a privileged effect without verifying that the sender is the operator, while a sibling handler in the same repo does.
Recommendation
Update the @agenticmail/core package to the latest compatible version. Followings are version details:
- Affected version(s): < 0.9.43
- Patched version(s): 0.9.43
References
Could your website be exposed too?
SmartScanner can check your website for AgenticMail: Unauthenticated inbound mail triggers bypassPermissions resume of the operator's Claude Code session (bridg and gives you actionable findings to investigate.
Start a free scanRelated Issues
- @siteboon/claude-code-ui Vulnerable to Unauthenticated RCE via WebSocket Shell Injection - CVE-2026-31975
- DbGate: Unauthenticated Remote Code Execution via JSON Script Runner - CVE-2026-47668
- [Eclipse Theia] Data Exfiltration via Markdown Image Rendering in AI Chat - @theia/ai-claude-code - CVE-2026-22551
- AgenticMail API/storage and outbound relay hardening fixes - CVE-2026-47255


