๐Ÿ” CVE Alert

CVE-2026-50287

UNKNOWN 0.0

Missing Authentication for Critical Function in @agenticmail/mcp

CVSS Score
0.0
EPSS Score
0.1%
EPSS Percentile
19th

AgenticMail gives AI agents real email addresses and phone numbers. Prior to version 0.9.27, @agenticmail/mcp exposes a Streamable HTTP transport when started with --http or MCP_HTTP=1. In that mode, the /mcp endpoint accepts requests without any HTTP authentication layer. A remote client can initialize a session and call tools directly. This issue has been patched in version 0.9.27.

CWE CWE-306
Vendor agenticmail
Product agenticmail
Published Jun 12, 2026
Stay Ahead of the Next One

Get instant alerts for agenticmail agenticmail

Be the first to know when new unknown vulnerabilities affecting agenticmail agenticmail are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

agenticmail / agenticmail
< 0.9.27

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/agenticmail/agenticmail/security/advisories/GHSA-63gr-g7jc-v8rg