CVE-2026-47255: AgenticMail gives AI agents real email addresses and phone numbers. @agenticmail/api prior to version 0.9.32 and @agenti
Summary
AgenticMail is a system that provides AI agents with real email addresses and phone numbers, but older versions (API before 0.9.32 and core before 0.9.10) had multiple security weaknesses. These weaknesses included problems with validating user permissions, checking database queries for safety, verifying secure connections, and controlling special characters in email commands, which could allow unauthorized access to email data.
Solution / Mitigation
@agenticmail/api should be updated to version 0.9.32 or later, and @agenticmail/core should be updated to version 0.9.10 or later.
Vulnerability Details
8.2(high)
EPSS: 0.0%
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L
network
low
none
none
July 20, 2026
Classification
Affected Vendors
Related Issues
GHSA-382c-vx95-w3p5: Gittensory: Missing contributor-scoped access control on profile endpoint and MCP tool leaks miner financial data
CVE-2025-45150: Insecure permissions in LangChain-ChatGLM-Webui commit ef829 allows attackers to arbitrarily view and download sensitive
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-47255
First tracked: July 20, 2026 at 08:07 PM
Classified by LLM (prompt v3) · confidence: 78%