Inbox Zero is an AI personal assistant for email. Prior to 2.29.3, the cleaner email stream endpoint used a shared Redis subscription listener, which could deliver thread events for one authenticated account to another authenticated account using the cleaner feature at the same time. This vulnerability is fixed in 2.29.3.
References
| Link | Resource |
|---|---|
| https://github.com/elie222/inbox-zero/commit/02341923b5460ce9630c4681a9b6461ba466688a | Patch |
| https://github.com/elie222/inbox-zero/security/advisories/GHSA-f3gp-v7cj-2569 | Patch Vendor Advisory |
Configurations
History
21 May 2026, 18:03
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Getinboxzero inbox Zero
Getinboxzero |
|
| CPE | cpe:2.3:a:getinboxzero:inbox_zero:*:*:*:*:*:*:*:* | |
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 4.3 |
| CWE | NVD-CWE-noinfo | |
| References | () https://github.com/elie222/inbox-zero/commit/02341923b5460ce9630c4681a9b6461ba466688a - Patch | |
| References | () https://github.com/elie222/inbox-zero/security/advisories/GHSA-f3gp-v7cj-2569 - Patch, Vendor Advisory |
11 May 2026, 18:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-05-11 18:16
Updated : 2026-05-21 18:03
NVD link : CVE-2026-42865
Mitre link : CVE-2026-42865
CVE.ORG link : CVE-2026-42865
JSON object : View
Products Affected
getinboxzero
- inbox_zero
CWE
