CVE-2026-42865
Vulnerability Description
Inbox Zero is an AI personal assistant for email. Prior to 2.29.3, the cleaner email stream endpoint used a shared Redis subscription listener, which could deliver thread events for one authenticated account to another authenticated account using the cleaner feature at the same time. This vulnerability is fixed in 2.29.3.
Vulnerability Details
Published Date
Last Modified
CWE ID
CWE-200
Source
NVD
Vendor
elie222
Product
inbox-zero
Discussion (0)
Add Comment
No comments yet. Be the first!