AgenticMail是AgenticMail公司的一款面向人工智能代理的电子邮件、短信和电话基础设施。 AgenticMail 0.9.64之前版本存在授权问题漏洞,该漏洞源于授权绕过问题,允许低权限认证代理通过向GET /api/agenticmail/tasks/pending接口提供目标代理名称枚举其他代理的待办/已认领任务,获取任务ID和有效载荷,进而利用任务变异端点跨代理认领、完成或失败任务,导致预期的能力模型失效。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| agenticmail | @agenticmail/api | < 0.9.64 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| agenticmail | @agenticmail/api | < 0.9.64 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-47255 | 8.2 HIGH | AgenticMail API/storage and outbound relay hardening |
| CVE-2026-57495 | AgenticMail: Unauthenticated inbound mail triggers bypassPermissions resume of the operato |
No comments yet