Executive brief
Inbox Zero, an AI-powered email management assistant, contained a flaw in its 'cleaner' feature that could allow one user to see email thread events belonging to another user. This occurred when two different authenticated users were using the email cleaning tool at the same time. While the risk was limited to users of this specific feature, it could have resulted in the unauthorized exposure of private email metadata between accounts.
Technical details
A race condition or shared resource flaw existed in the 'cleaner' email stream endpoint of Inbox Zero. The application utilized a shared Redis subscription listener for Server-Sent Events (SSE), which failed to properly isolate message streams between different authenticated sessions. Consequently, if multiple authenticated users accessed the cleaner feature simultaneously, Redis could broadcast thread events (CWE-200) to the incorrect subscriber. The vulnerability is present in versions up to 2.29.2 and was addressed in version 2.29.3 by isolating SSE subscriptions.
Affected products
- elie222 Inbox Zero <= 2.29.2
Timeline
- 2026-04-24: patched: Fix committed to main branch
- 2026-05-11: disclosed: Advisory published via GitHub and NVD