{"id":"CVE-2026-47255","summary":"AgenticMail API/storage and outbound relay hardening","details":"AgenticMail gives AI agents real email addresses and phone numbers. @agenticmail/api prior to version 0.9.32 and @agenticmail/core prior to version 0.9.10 had weakness related to validation and and binding of inactive-agent hour filtering; storage SQL identifier validation; metadata-backed ownership checks for raw storage SQL; blocking direct storage metadata access through raw SQL; fail-closed outbound worker secret handling; SMTP envelope/header control-character validation before command construction; and TLS certificate verification as the default for MailSender with an explicit opt-out for local development. @agenticmail/api prior to version 0.9.32 and @agenticmail/core prior to version 0.9.10 are patched.","aliases":["GHSA-wjjv-3mj2-39hf"],"modified":"2026-07-25T03:56:17.178517607Z","published":"2026-07-20T21:56:40.252Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/47xxx/CVE-2026-47255.json","cna_assigner":"GitHub_M","cwe_ids":["CWE-20","CWE-284","CWE-319","CWE-798","CWE-89"]},"references":[{"type":"WEB","url":"https://github.com/agenticmail/agenticmail/blob/7b9b05d973676e9f3d097c08b8e649f59bfc15d0/CHANGELOG.md?plain=1#L1842"},{"type":"WEB","url":"https://github.com/agenticmail/agenticmail/blob/7b9b05d973676e9f3d097c08b8e649f59bfc15d0/packages/core/src/mail/sender.ts#L33"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/47xxx/CVE-2026-47255.json"},{"type":"ADVISORY","url":"https://github.com/agenticmail/agenticmail/security/advisories/GHSA-wjjv-3mj2-39hf"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-47255"},{"type":"FIX","url":"https://github.com/agenticmail/agenticmail/commit/1408de543fa3577d8c2d4fdb289c75fe6faafac7"},{"type":"FIX","url":"https://github.com/agenticmail/agenticmail/commit/234b811e426a0743170f3b10bc43419d64330155"},{"type":"FIX","url":"https://github.com/agenticmail/agenticmail/commit/6c70c8254c906f823392d7f5ccee88a5481e7731"},{"type":"FIX","url":"https://github.com/agenticmail/agenticmail/commit/8cb053f2307dd77b7736ffa0d7df04b0ccc3272d"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/agenticmail/agenticmail","events":[{"introduced":"0"},{"fixed":"2f5354a32019d703be1e0b3524552f1c79324237"},{"fixed":"7eb4e2d0c655d731a99c2f50285d14dea7574d43"},{"fixed":"1408de543fa3577d8c2d4fdb289c75fe6faafac7"},{"fixed":"234b811e426a0743170f3b10bc43419d64330155"},{"fixed":"6c70c8254c906f823392d7f5ccee88a5481e7731"},{"fixed":"8cb053f2307dd77b7736ffa0d7df04b0ccc3272d"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"0.9.32"},{"fixed":"0.9.10"}],"source":["AFFECTED_FIELD","REFERENCES"]}}],"versions":["v0.9.48","v0.9.47","v0.9.46","v0.9.45","v0.9.39","v0.9.38","v0.9.37","v0.9.36","v0.9.35","v0.9.34","v0.9.33","v0.9.32","v0.9.31","v0.9.30","v0.9.29","v0.9.28","v0.9.27","v0.9.26","v0.9.25","v0.9.24","v0.9.23","v0.9.22","v0.9.21","v0.9.20","v0.9.19","v0.9.18","v0.9.17","v0.9.16","v0.9.15","v0.9.14","v0.9.13","v0.9.12","v0.9.11","v0.9.10","v0.9.9","v0.9.8","v0.9.7","v0.9.6","v0.9.5","v0.9.4","v0.9.3","v0.9.2","v0.9.1","v0.9.0","v0.8.36","v0.8.35","v0.8.34","v0.8.33","v0.8.32","v0.8.31","v0.8.30","v0.8.29","v0.8.28","v0.8.27","v0.8.26","v0.8.25","v0.8.24","v0.8.23","v0.8.22","v0.8.21","v0.8.19","v0.8.18","v0.8.16","v0.8.15","v0.8.14","v0.8.13","v0.8.12","v0.8.11","plugin-v0.8.10","v0.8.10","v0.8.9","v0.8.8","v0.8.7","v0.8.6","v0.8.5","v0.8.4","v0.8.3","v0.8.2","v0.5.62","v0.5.61","v0.5.60","v0.5.59","v0.5.58","v0.5.57","v0.5.56","v0.5.55","v0.5.54","v0.5.53","v0.5.52","v0.5.51","v0.5.50","v0.5.44","v0.5.43","v0.5.42","v0.5.41","v0.5.40","v0.5.39","v0.5.38","v0.5.37","v0.5.34","v0.4.0","v0.3.25"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-47255.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L"}]}