GHSA-hjwc-26pj-v3pmHigh▾ TwilightAgenticMail: Cross-agent task authorization bypass in AgenticMail API
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
A low-privileged authenticated AgenticMail agent can enumerate another agent's pending/claimed tasks by supplying the target agent name to GET /api/agenticmail/tasks/pending?assignee=<name>. The returned task objects include the task IDs and payloads. The same task IDs can then be used with the capability-style task mutation endpoints (/tasks/:id/claim, /tasks/:id/result, /tasks/:id/complete, /tasks/:id/fail) to claim, complete, or fail tasks assigned to a different agent.
Because ordinary authenticated agents can discover agent names through GET /api/agenticmail/accounts/directory, the task ID effectively stops being a secret capability. This turns the intended capability model into a cross-agent authorization bypass.
Package: @agenticmail/api
Observed version: 0.9.62
Repository: agenticmail/agenticmail
Relevant code paths:
packages/api/src/app.ts: createAuthMiddleware(...) is mounted before createAccountRoutes(...) and createTaskRoutes(...), so these routes are reachable by any valid bearer token.packages/api/src/routes/accounts.ts: GET /accounts/directory is available to any authenticated user and returns agent names.packages/api/src/routes/tasks.ts: GET /tasks/pending?assignee=name resolves arbitrary agent names and returns that agent's pending/claimed tasks.packages/api/src/routes/tasks.ts: /tasks/:id/claim, /tasks/:id/result, /tasks/:id/complete, /tasks/:id/fail, and /tasks/:id do not check whether the authenticated caller is the task assignee, assigner, or otherwise authorized for the task.An attacker only needs a valid agent API key. They can:
/accounts/directory./tasks/pending?assignee=<victimName>.I reproduced this locally with a focused Vitest test mounted directly on createTaskRoutes. The test creates two agents, Alice and Bob, and one pending task assigned to Bob. Alice authenticates with her own agent key and performs the following sequence:
GET /api/agenticmail/tasks/pending?assignee=Bob with Authorization: Bearer ak_alice.task-for-bob, { "task": "secret task intended for Bob" }.POST /api/agenticmail/tasks/task-for-bob/complete with her own bearer token and an attacker-controlled result.completed and the stored result is controlled by Alice.The local verification command was:
npm run test --workspace=@agenticmail/api -- task-routes-authz.test.ts
Result:
PASS src/__tests__/task-routes-authz.test.ts (1 test)
Task listing and task mutation endpoints should enforce an authorization relationship between the authenticated caller and the task. For example:
GET /tasks/pending?assignee=<name> should either be restricted to the current agent, master/admin callers, or an explicit delegated relationship./tasks/:id/claim, /tasks/:id/result, /tasks/:id/complete, /tasks/:id/fail, and /tasks/:id should verify that the caller is the assignee, assigner, master/admin, or otherwise explicitly authorized.Please credit the finder as: Yaohui Wang
@agenticmail/api < 0.9.64Upgrade to a patched release:
@agenticmail/api 0.9.64Connected by shared product, vendor, weakness, or advisory.
CVE-2026-55178High· 7.5GeoLens is a self-hosted geospatial data catalog with semantic search, OGC and STAC APIs, and a map builder
CVE-2026-54052Critical· 9.9n8n-MCP: Cross-tenant access to workflow version backups in multi-tenant HTTP deployments
CVE-2026-52850Medium· 4.3Docmost is open-source collaborative wiki and documentation software
CVE-2026-54671High· 8.8WeGIA is a web manager for charitable institutions
CVE-2026-53546Critical· 9.6Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities
CVE-2026-18121Medium· 6.3Concrete CMS 9.5.2 and below is vulnerable to an authorization bypass (IDOR) because the frontend calendar lightbox endpoint (/ccm/calendar/view_event/{bID}/{occurrence_id}) does not verify that the caller is permitted to view the calend…