PT-2026-61739 · Npm · @Agenticmail/Claudecode+3

CVE-2026-57495

·

Published

2026-06-18

·

Updated

2026-07-21

CVSS v4.0

8.2

High

VectorAV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions @agenticmail/claudecode versions prior to 0.2.39 @agenticmail/codex versions prior to 0.1.33 @agenticmail/core versions prior to 0.9.43 @agenticmail/openclaw versions prior to 0.5.71
Description Two inbound-mail handlers execute privileged effects without verifying if the sender is the operator. Specifically, any external email sent to the bridge inbox triggers the dispatcher to resume the operator's Claude Code session using permissionMode: 'bypassPermissions'. This allows an attacker to embed controlled content from the from, subject, and preview variables directly into the prompt read by the resumed agent. This results in an indirect prompt injection into a fully-privileged agent—possessing Bash, Write, Edit, and WebFetch capabilities along with the agenticmail MCP toolbelt—operating under the operator's OAuth identity.
Recommendations Update @agenticmail/claudecode to version 0.2.39 or later. Update @agenticmail/codex to version 0.1.33 or later. Update @agenticmail/core to version 0.9.43 or later. Update @agenticmail/openclaw to version 0.5.71 or later.

Fix

Missing Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-57495
GHSA-FQ4X-789W-JG5H

Affected Products

@Agenticmail/Claudecode
@Agenticmail/Codex
@Agenticmail/Core
@Agenticmail/Openclaw