Junglewise Threat Intelligence

AgenticMail API cross-agent task authorization bypass

Severity: high · CVSS 7.1 · Published 2026-06-18

Technologies: @agenticmail/api (npm). Vendors: npm.

Executive brief

AgenticMail is an API used for managing automated agent tasks. A security flaw allows any authenticated agent to view and manipulate tasks belonging to other agents. An attacker could use this to steal sensitive data contained in task payloads or interfere with business operations by falsely completing or failing tasks.

Technical details

The vulnerability consists of a missing authorization check (CWE-862) and an insecure direct object reference (CWE-639) in the `@agenticmail/api` package. An authenticated attacker can first use the `/accounts/directory` endpoint to discover other agent names. By passing these names to the `GET /tasks/pending?assignee=<name>` endpoint, the attacker can retrieve task IDs and sensitive payloads for other agents. Because the task mutation endpoints (claim, result, complete, fail) do not verify if the caller is the authorized assignee or assigner, the attacker can use the leaked task IDs to modify the state of tasks they do not own. This is patched in version 0.9.64.

Affected products

  • AgenticMail @agenticmail/api < 0.9.64

Timeline

  • 2026-06-18: disclosed
  • 2026-06-18: advisory
  • 0.9.64: patched

References

Related threats