{"data":{"id":"0bb79dbf-4ae5-47af-a1e7-68726b1d8ff9","title":"CVE-2026-47255: AgenticMail gives AI agents real email addresses and phone numbers. @agenticmail/api prior to version 0.9.32 and @agenti","summary":"AgenticMail is a system that provides AI agents with real email addresses and phone numbers, but older versions (API before 0.9.32 and core before 0.9.10) had multiple security weaknesses. These weaknesses included problems with validating user permissions, checking database queries for safety, verifying secure connections, and controlling special characters in email commands, which could allow unauthorized access to email data.","solution":"@agenticmail/api should be updated to version 0.9.32 or later, and @agenticmail/core should be updated to version 0.9.10 or later.","labels":["security"],"sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-47255","publishedAt":"2026-07-20T22:17:15.403Z","cveId":"CVE-2026-47255","cweIds":["CWE-20","CWE-89","CWE-284","CWE-319","CWE-798"],"cvssScore":"8.2","cvssSeverity":"high","severity":"high","attackType":["data_extraction","pii_leakage"],"issueType":"vulnerability","affectedPackages":null,"affectedVendors":[],"affectedVendorsRaw":["AgenticMail"],"classifierModel":"claude-haiku-4-5-20251001","classifierPromptVersion":"v3","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L","attackVector":"network","attackComplexity":"low","privilegesRequired":"none","userInteraction":"none","exploitMaturity":"unknown","epssScore":0,"patchAvailable":null,"disclosureDate":"2026-07-20T22:17:15.403Z","capecIds":["CAPEC-66"],"crossRefCount":0,"attackSophistication":"moderate","impactType":["confidentiality","integrity"],"aiComponentTargeted":"agent","llmSpecific":false,"classifierConfidence":0.78,"researchCategory":null,"atlasIds":null}}