Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
AgenticMail API/storage and outbound relay hardening
Vulnerability Description
AgenticMail gives AI agents real email addresses and phone numbers. @agenticmail/api prior to version 0.9.32 and @agenticmail/core prior to version 0.9.10 had weakness related to validation and and binding of inactive-agent hour filtering; storage SQL identifier validation; metadata-backed ownership checks for raw storage SQL; blocking direct storage metadata access through raw SQL; fail-closed outbound worker secret handling; SMTP envelope/header control-character validation before command construction; and TLS certificate verification as the default for MailSender with an explicit opt-out for local development. @agenticmail/api prior to version 0.9.32 and @agenticmail/core prior to version 0.9.10 are patched.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L
Vulnerability Type
输入验证不恰当
Vulnerability Title
AgenticMail 输入验证错误漏洞
Vulnerability Description
AgenticMail是AgenticMail公司的一款面向人工智能代理的电子邮件、短信和电话基础设施。 AgenticMail 0.9.32之前版本和@agenticmail/core 0.9.10之前版本存在安全漏洞,该漏洞源于输入验证和绑定、SQL标识符验证、元数据所有权检查、原始SQL存储访问控制、出站工作者密钥处理、SMTP命令控制字符验证以及TLS证书验证等多个方面存在缺陷,可能导致完整性受损和可用性降低。
CVSS Information
N/A
Vulnerability Type
N/A