CVE-2026-47255
agenticmail · @agenticmail/api and @agenticmail/core
AgenticMail contains multiple vulnerabilities including improper input validation, SQL injection, and broken access controls.
Executive summary
Critical security flaws in AgenticMail allow unauthenticated attackers to perform SQL injection and bypass access controls, potentially compromising sensitive email and contact data.
Vulnerability
The software suffers from improper input validation, SQL injection, and improper access control. These vulnerabilities are exploitable by an unauthenticated attacker, allowing them to manipulate database queries and gain unauthorized access to protected resources.
Business impact
The combination of SQL injection and access control failures presents a severe risk of data exfiltration and unauthorized modification of sensitive information. With a CVSS score of 8.2, this vulnerability is categorized as High and represents a significant risk to the confidentiality and integrity of the AI agent platform.
Remediation
Immediate Action: Update @agenticmail/api to version 0.9.32 and @agenticmail/core to version 0.9.10 or higher immediately.
Proactive Monitoring: Review database query logs for unusual patterns or syntax that may indicate SQL injection attempts.
Compensating Controls: Deploy a Web Application Firewall (WAF) with rules configured to detect and block common SQL injection payloads and unauthorized API access attempts.
Exploitation status
Public Exploit Available: No (unknown)
Analyst recommendation
Organizations utilizing AgenticMail must immediately upgrade their packages to the versions specified above. Failure to remediate these flaws leaves the application vulnerable to full database compromise and unauthorized data access.