CVE 2.3 LOW

Inbox Zero: Cross-account cleaner email stream exposure_CVE-2026-42865

2.3 / 10
LOW
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N

Description

Inbox Zero is an AI personal assistant for email. Prior to 2.29.3, the cleaner email stream endpoint used a shared Redis subscription listener, which could deliver thread events for one authenticated account to another authenticated account using the cleaner feature at the same time. This vulnerability is fixed in 2.29.3.

Basic Information

ID CVE-2026-42865
Source GitHub_M
Published May 11, 2026 at 17:53

Affected Product

Vendor elie222
Product inbox-zero
Version < 2.29.3
Affected Versions elie222 inbox-zero < 2.29.3

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.