Executive brief
AgenticMail, a tool that provides AI agents with email and phone capabilities, contains a security flaw in its Model Context Protocol (MCP) component. When configured to run over HTTP, the system fails to require authentication, allowing anyone on the network to perform administrative actions. An attacker could exploit this to delete agents, hijack email relays, or access sensitive configuration data without needing a password or master key.
Technical details
A missing authentication vulnerability (CWE-306) exists in @agenticmail/mcp prior to version 0.9.27. When the MCP server is started with the --http flag or MCP_HTTP=1 environment variable, the /mcp endpoint exposes a Streamable HTTP transport that does not validate Authorization headers. Because the server process forwards tool calls using its own internal AGENTICMAIL_MASTER_KEY, an unauthenticated remote attacker can initialize a session and invoke high-privilege tools. Impacted tools include setup_email_relay, delete_agent, and cleanup_agents. The issue is resolved in version 0.9.27 by implementing proper authentication layers for the HTTP transport.
Affected products
- AgenticMail @agenticmail/mcp < 0.9.27
Timeline
- 2026-05-29: advisory: GitHub Security Advisory published
- 2026-06-12: disclosed: CVE published to NVD