CVE-2026-57495: Agenticmail @agenticmail/claudecode

High severity, CVSS 8.2. EPSS: 0.4% chance of exploitation in the next 30 days.

AgenticMail gives AI agents real email addresses and phone numbers. In @agenticmail/claudecode prior to version 0.2.39, @agenticmail/codex prior to version 0.1.33, @agenticmail/core prior to version 0.9.43, and @agenticmail/openclaw prior to version 0.5.71, two inbound-mail handlers act on a privileged effect without verifying that the sender is the operator, while a sibling handler in the same repo does. The higher-impact one: any external email routed to the bridge inbox causes the dispatcher to resume the operator's Claude Code session with `permissionMode: 'bypassPermissions'`, embedding the attacker-controlled `from`/`subject`/`preview` verbatim into the prompt the resumed agent reads — an indirect prompt injection into a fully-privileged agent (Bash/Write/Edit/WebFetch + the agenticmail MCP toolbelt) running as the operator's OAuth identity. The sibling operator-query email-reply hook gates the same untrusted-From provenance with `isOperatorReplySender(replyFrom, config.operatorEmail)` (fail-closed); the bridge-wake path — a strictly higher-privilege effect — has no equivalent. @agenticmail/claudecode 0.2.39, @agenticmail/codex 0.1.33, @agenticmail/core 0.9.43, and @agenticmail/openclaw 0.5.71 contain a fix.

Affected products

  • Agenticmail @agenticmail/claudecode: before 0.2.39 (fixed in 0.2.39)
  • Agenticmail @agenticmail/codex: before 0.1.33 (fixed in 0.1.33)
  • Agenticmail @agenticmail/core: before 0.9.43 (fixed in 0.9.43)
  • Agenticmail @agenticmail/openclaw: before 0.5.71 (fixed in 0.5.71)

Published 2026-07-20. Last modified 2026-07-23.