{
  "affected": [
    {
      "ranges": [
        {
          "database_specific": {
            "extracted_events": [
              {
                "introduced": "0"
              },
              {
                "fixed": "0.9.32"
              },
              {
                "fixed": "0.9.10"
              }
            ],
            "source": [
              "AFFECTED_FIELD",
              "REFERENCES"
            ]
          },
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "2f5354a32019d703be1e0b3524552f1c79324237"
            },
            {
              "fixed": "7eb4e2d0c655d731a99c2f50285d14dea7574d43"
            },
            {
              "fixed": "1408de543fa3577d8c2d4fdb289c75fe6faafac7"
            },
            {
              "fixed": "234b811e426a0743170f3b10bc43419d64330155"
            },
            {
              "fixed": "6c70c8254c906f823392d7f5ccee88a5481e7731"
            },
            {
              "fixed": "8cb053f2307dd77b7736ffa0d7df04b0ccc3272d"
            }
          ],
          "repo": "https://github.com/agenticmail/agenticmail",
          "type": "GIT"
        }
      ]
    }
  ],
  "aliases": [
    "GHSA-wjjv-3mj2-39hf"
  ],
  "database_specific": {
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
      "CWE-20",
      "CWE-284",
      "CWE-319",
      "CWE-798",
      "CWE-89"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/47xxx/CVE-2026-47255.json"
  },
  "details": "AgenticMail gives AI agents real email addresses and phone numbers. @agenticmail/api prior to version 0.9.32 and @agenticmail/core prior to version 0.9.10 had weakness related to validation and and binding of inactive-agent hour filtering; storage SQL identifier validation; metadata-backed ownership checks for raw storage SQL; blocking direct storage metadata access through raw SQL; fail-closed outbound worker secret handling; SMTP envelope/header control-character validation before command construction; and TLS certificate verification as the default for MailSender with an explicit opt-out for local development. @agenticmail/api prior to version 0.9.32 and @agenticmail/core prior to version 0.9.10 are patched.",
  "id": "CVE-2026-47255",
  "modified": "2026-07-25T03:56:17.178517607Z",
  "published": "2026-07-20T21:56:40.252Z",
  "references": [
    {
      "type": "WEB",
      "url": "https://github.com/agenticmail/agenticmail/blob/7b9b05d973676e9f3d097c08b8e649f59bfc15d0/CHANGELOG.md?plain=1#L1842"
    },
    {
      "type": "WEB",
      "url": "https://github.com/agenticmail/agenticmail/blob/7b9b05d973676e9f3d097c08b8e649f59bfc15d0/packages/core/src/mail/sender.ts#L33"
    },
    {
      "type": "ADVISORY",
      "url": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/47xxx/CVE-2026-47255.json"
    },
    {
      "type": "ADVISORY",
      "url": "https://github.com/agenticmail/agenticmail/security/advisories/GHSA-wjjv-3mj2-39hf"
    },
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-47255"
    },
    {
      "type": "FIX",
      "url": "https://github.com/agenticmail/agenticmail/commit/1408de543fa3577d8c2d4fdb289c75fe6faafac7"
    },
    {
      "type": "FIX",
      "url": "https://github.com/agenticmail/agenticmail/commit/234b811e426a0743170f3b10bc43419d64330155"
    },
    {
      "type": "FIX",
      "url": "https://github.com/agenticmail/agenticmail/commit/6c70c8254c906f823392d7f5ccee88a5481e7731"
    },
    {
      "type": "FIX",
      "url": "https://github.com/agenticmail/agenticmail/commit/8cb053f2307dd77b7736ffa0d7df04b0ccc3272d"
    }
  ],
  "schema_version": "1.8.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L",
      "type": "CVSS_V3"
    }
  ],
  "summary": "AgenticMail API/storage and outbound relay hardening"
}