NONE · 0

CVE-2026-50287

AgenticMail gives AI agents real email addresses and phone numbers. Prior to version 0.9.27, @agenticmail/mcp exposes a Streamable HTTP transport when started with --http or MCP_HTTP=1. In that mode, ...

Vulnerability Description

AgenticMail gives AI agents real email addresses and phone numbers. Prior to version 0.9.27, @agenticmail/mcp exposes a Streamable HTTP transport when started with --http or MCP_HTTP=1. In that mode, the /mcp endpoint accepts requests without any HTTP authentication layer. A remote client can initialize a session and call tools directly. This issue has been patched in version 0.9.27.

Related Weaknesses (CWE)

References

FAQ

What is CVE-2026-50287?

CVE-2026-50287 is a documented vulnerability. AgenticMail gives AI agents real email addresses and phone numbers. Prior to version 0.9.27, @agenticmail/mcp exposes a Streamable HTTP transport when started with --http or MCP_HTTP=1. In that mode, ...

How severe is CVE-2026-50287?

CVSS scoring is not yet available for CVE-2026-50287. Check NVD for updates.

Is there a patch for CVE-2026-50287?

Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.