Vulnerabilities/

AgenticMail: Unauthenticated inbound mail triggers bypassPermissions resume of the operator's Claude Code session (bridg

Severity:
High

Description

Two inbound-mail handlers act on a privileged effect without verifying that the sender is the operator, while a sibling handler in the same repo does.

Recommendation

Update the @agenticmail/core package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
@agenticmail/core
Anything's wrong? Let us know Last updated on July 21, 2026