CVE-2026-47255 Details
Description
AgenticMail gives AI agents real email addresses and phone numbers. @agenticmail/api prior to version 0.9.32 and @agenticmail/core prior to version 0.9.10 had weakness related to validation and and binding of inactive-agent hour filtering; storage SQL identifier validation; metadata-backed ownership checks for raw storage SQL; blocking direct storage metadata access through raw SQL; fail-closed outbound worker secret handling; SMTP envelope/header control-character validation before command construction; and TLS certificate verification as the default for MailSender with an explicit opt-out for local development. @agenticmail/api prior to version 0.9.32 and @agenticmail/core prior to version 0.9.10 are patched.
A vulnerability exists in AgenticMail's API and core packages prior to versions 0.9.32 and 0.9.10, respectively. The issue stems from inadequate validation and management of inactive-agent hour filtering, which could disrupt normal operations. Additionally, the vulnerability allows SQL injection through raw storage SQL access, bypassing ownership checks and direct metadata table access, which could lead to unauthorized data manipulation or exposure.
Users can upgrade to '@agenticmail/[email protected]' and '@agenticmail/[email protected]' to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jul 20, 2026CISA-ADP
Assessed Jul 21, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-20 | Improper Input Validation | [email protected] |
| CWE-284 | Improper Access Control | [email protected] |
| CWE-319 | Cleartext Transmission of Sensitive Information | [email protected] |
| CWE-798 | Use of Hard-coded Credentials | [email protected] |
| CWE-89 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| AgenticMail | <= 0.9.31 (semver) |
CPE
Remediation
| |
| AgenticMail API | <= 0.9.31 (semver) |
CPE
Remediation
| |
| AgenticMail Core | <= 0.9.9 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 21, 2026 | CVE Modified | CISA-ADP |
| Jul 20, 2026 | New CVE Received | [email protected] |
Volerion