Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-wjjv-3mj2-39hf | AgenticMail API/storage and outbound relay hardening fixes |
Tue, 28 Jul 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Agenticmail
Agenticmail agenticmail Agenticmail api |
|
| Vendors & Products |
Agenticmail
Agenticmail agenticmail Agenticmail api |
Tue, 21 Jul 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 20 Jul 2026 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | AgenticMail gives AI agents real email addresses and phone numbers. @agenticmail/api prior to version 0.9.32 and @agenticmail/core prior to version 0.9.10 had weakness related to validation and and binding of inactive-agent hour filtering; storage SQL identifier validation; metadata-backed ownership checks for raw storage SQL; blocking direct storage metadata access through raw SQL; fail-closed outbound worker secret handling; SMTP envelope/header control-character validation before command construction; and TLS certificate verification as the default for MailSender with an explicit opt-out for local development. @agenticmail/api prior to version 0.9.32 and @agenticmail/core prior to version 0.9.10 are patched. | |
| Title | AgenticMail API/storage and outbound relay hardening | |
| Weaknesses | CWE-20 CWE-284 CWE-319 CWE-798 CWE-89 |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-07-21T14:06:27.159Z
Reserved: 2026-05-18T23:03:37.228Z
Link: CVE-2026-47255
Updated: 2026-07-21T14:06:21.965Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-07-29T00:30:17Z
Github GHSA