Email Handling Vulnerability in AgenticMail by Agentic
CVE-2026-57495

8.2HIGH

What is CVE-2026-57495?

A vulnerability exists in AgenticMail affecting certain modules where inbound-mail handlers process requests with insufficient verification of the sender's identity. This flaw allows an external attacker to manipulate the session of a privileged agent by routing external email to the bridge inbox, potentially leading to unauthorized actions being executed under the operator's identity. Key modules like @agenticmail/claudecode, @agenticmail/codex, @agenticmail/core, and @agenticmail/openclaw have pending fixes in their respective versions. The issue is fueled by the lack of proper checks in one handler compared to its sibling handler, which could inadvertently expose sensitive operations to unauthorized influence.

Affected Version(s)

@agenticmail/claudecode < 0.2.39

@agenticmail/codex < 0.1.33

@agenticmail/core < 0.9.43

References

CVSS V4

Score:
8.2
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.