Impact
AgenticMail supplies AI agents with authentic email addresses and phone numbers. Versions prior to 0.9.32 of @agenticmail/api and before 0.9.10 of @agenticmail/core contain several validation and binding weaknesses. These include insufficient filtering of inactive‑agent hours, failure to validate storage SQL identifiers, inadequate metadata‑backed ownership checks for raw storage SQL, permissive direct storage metadata access via raw SQL, fail‑closed outbound worker secret handling, lack of validation for SMTP envelope and header control characters before command construction, and default TLS certificate verification that can be opted out for local development. These flaws allow an attacker to potentially read sensitive data, manipulate mail transport behavior, or inject SQL queries, leading to data exposure and possible further exploitation. The affected components are patched from version 0.9.32 and 0.9.10 onward.
Affected Systems
Affected products are AgenticMail API and AgenticMail Core under the agenticmail organization. Versions earlier than API 0.9.32 and Core 0.9.10 are vulnerable, while subsequent releases contain the fixes documented by the vendor.
Risk and Exploitability
The EPSS score of < 1 % indicates a very low probability of widespread exploitation at present, and the vulnerability is not listed in the CISA KEV catalog. The CVSS score of 8.2 signals high severity, implying significant impact if exploitation succeeds. Attackers would need to interact with the vulnerable API endpoints or gain from raw SQL access; the exact vector is inferred from the description rather than directly stated. Given the lack of evidence for active exploitation, monitoring is advised while promptly applying the vendor’s patch.
OpenCVE Enrichment
Github GHSA