Email Personal Assistant Vulnerability in Inbox Zero by Elie222
CVE-2026-42865
2.3LOW
What is CVE-2026-42865?
The Inbox Zero personal assistant for email, prior to version 2.29.3, was affected by a vulnerability wherein the cleaner email stream endpoint utilized a shared Redis subscription listener. This misconfiguration allowed thread events intended for one authenticated account to be inadvertently delivered to another authenticated account using the cleaner feature simultaneously, thereby compromising user privacy and security. The issue has been rectified in the latest version 2.29.3.
Affected Version(s)
inbox-zero < 2.29.3
