{"id":"CVE-2026-57494","aliases":["GHSA-hjwc-26pj-v3pm"],"url":"https://o3.security/vulnerability/CVE-2026-57494","summary":"AgenticMail: Cross-agent task authorization bypass in AgenticMail API","details":"AgenticMail gives AI agents real email addresses and phone numbers. In @agenticmail/api prior to version 0.9.64, a low-privileged authenticated AgenticMail agent can enumerate another agent's pending/claimed tasks by supplying the target agent name to `GET /api/agenticmail/tasks/pending?assignee=<name>`. The returned task objects include the task IDs and payloads. The same task IDs can then be used with the capability-style task mutation endpoints (`/tasks/:id/claim`, `/tasks/:id/result`, `/tasks/:id/complete`, `/tasks/:id/fail`) to claim, complete, or fail tasks assigned to a different agent. Because ordinary authenticated agents can discover agent names through `GET /api/agenticmail/accounts/directory`, the task ID effectively stops being a secret capability. This turns the intended capability model into a cross-agent authorization bypass. Version 0.9.64 contains a fix.","published":"2026-07-20T22:01:43.891Z","modified":"2026-08-12T03:51:24.806163877Z","cvss":null,"epss":{"score":0.00372,"percentile":0.3018,"asOf":"2026-09-01"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"@agenticmail/api","fixedVersion":"0.9.64"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/57xxx/CVE-2026-57494.json"},{"type":"ADVISORY","url":"https://github.com/agenticmail/agenticmail/security/advisories/GHSA-hjwc-26pj-v3pm"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-57494"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:24.806163877Z"}}