PT-2026-48122 · Unknown · @Agenticmail/Mcp
CVE-2026-50287
·
Published
2026-06-01
·
Updated
2026-06-16
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
@agenticmail/mcp versions prior to 0.9.27
Description
When started with the
--http flag or the MCP HTTP=1 variable, the software exposes a Streamable HTTP transport. In this mode, the '/mcp' endpoint accepts requests without an HTTP authentication layer, allowing a remote client to initialize a session and call tools directly. This bypasses the authorization boundary intended for administrative and gateway operations, as the server forwards these calls using its own configured AGENTICMAIL MASTER KEY. Consequently, unauthenticated network clients can invoke master-key-only tools, such as setup email relay(), setup email domain(), delete agent(), cleanup agents(), and send test email().Recommendations
Update to version 0.9.27.
As a temporary workaround, avoid starting the server with the
--http flag or setting MCP HTTP=1 until the update is applied.Exploit
Fix
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
@Agenticmail/Mcp