AgenticMail: Unauthenticated inbound mail triggers bypassPermissions resume of the operator's Claude Code session (bridg
- Severity:
- High
Description
Two inbound-mail handlers act on a privileged effect without verifying that the sender is the operator, while a sibling handler in the same repo does.
Recommendation
Update the @agenticmail/core package to the latest compatible version. Followings are version details:
- Affected version(s): < 0.9.43
- Patched version(s): 0.9.43
References
Related Issues
- @siteboon/claude-code-ui Vulnerable to Unauthenticated RCE via WebSocket Shell Injection - CVE-2026-31975
- DbGate: Unauthenticated Remote Code Execution via JSON Script Runner - CVE-2026-47668
- [Eclipse Theia] Data Exfiltration via Markdown Image Rendering in AI Chat - @theia/ai-claude-code - CVE-2026-22551
- AgenticMail API/storage and outbound relay hardening fixes - CVE-2026-47255
You might also like:
- Tags:
- npm
- @agenticmail/core
Anything's wrong? Let us know Last updated on July 21, 2026


