2.3
/ 10
LOW
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Description
Inbox Zero is an AI personal assistant for email. Prior to 2.29.3, the cleaner email stream endpoint used a shared Redis subscription listener, which could deliver thread events for one authenticated account to another authenticated account using the cleaner feature at the same time. This vulnerability is fixed in 2.29.3.
Basic Information
ID
CVE-2026-42865
Source
GitHub_M
Published
May 11, 2026 at 17:53
Affected Product
Vendor
elie222
Product
inbox-zero
Version
< 2.29.3
Affected Versions
elie222 inbox-zero < 2.29.3