Email Handling Vulnerability in AgenticMail by Agentic
CVE-2026-57495
What is CVE-2026-57495?
A vulnerability exists in AgenticMail affecting certain modules where inbound-mail handlers process requests with insufficient verification of the sender's identity. This flaw allows an external attacker to manipulate the session of a privileged agent by routing external email to the bridge inbox, potentially leading to unauthorized actions being executed under the operator's identity. Key modules like @agenticmail/claudecode, @agenticmail/codex, @agenticmail/core, and @agenticmail/openclaw have pending fixes in their respective versions. The issue is fueled by the lack of proper checks in one handler compared to its sibling handler, which could inadvertently expose sensitive operations to unauthorized influence.
Affected Version(s)
@agenticmail/claudecode < 0.2.39
@agenticmail/codex < 0.1.33
@agenticmail/core < 0.9.43
