AgenticMail是AgenticMail公司的一款面向人工智能代理的电子邮件、短信和电话基础设施。 AgenticMail存在授权问题漏洞,该漏洞源于入站邮件处理程序在未验证发件人是操作员的情况下执行特权操作,可能导致将攻击者控制的邮件内容嵌入到恢复的Claude Code会话中,进行间接提示注入,影响完全特权代理的运行。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| agenticmail | @agenticmail/claudecode | < 0.2.39 |
affected |
| agenticmail | @agenticmail/codex | < 0.1.33 |
affected |
| agenticmail | @agenticmail/core | < 0.9.43 |
affected |
| agenticmail | @agenticmail/openclaw | < 0.5.71 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| agenticmail | @agenticmail/core | < 0.9.43 | - |
|
| agenticmail | @agenticmail/claudecode | < 0.2.39 | - |
|
| agenticmail | @agenticmail/codex | < 0.1.33 | - |
|
| agenticmail | @agenticmail/openclaw | < 0.5.71 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-47255 | 8.2 HIGH | AgenticMail API/storage and outbound relay hardening |
| CVE-2026-57494 | AgenticMail: Cross-agent task authorization bypass in AgenticMail API |
No comments yet