Description
PraisonAI is a multi-agent teams system. Prior to 4.6.59, the WhatsApp and Linear bot webhook handlers verify HMAC signatures only when WHATSAPP_APP_SECRET or LINEAR_WEBHOOK_SECRET is configured and otherwise parse and dispatch unsigned request bodies. A remote unauthenticated client that reaches the webhook route can forge messages, comments, or agent-session events, impersonate platform users, influence agent prompts and actions, and disrupt bot processing. This issue is fixed in 4.6.59.
Published: 2026-09-14
Score: 8.6 High
EPSS: < 1% Very Low
KEV: No
Impact: Forged inbound webhooks can impersonate users and manipulate bot behavior
Action: Immediate Patch
AI Analysis

Impact

The vulnerability lies in PraisonAI’s handling of WhatsApp and Linear webhook requests that omits signature verification when the secrets WHATSAPP_APP_SECRET or LINEAR_WEBHOOK_SECRET are not set, allowing unsigned request bodies to be parsed and dispatched. A remote unauthenticated client that reaches the webhook route can forge messages, comments, or agent‑session events, impersonate platform users, influence agent prompts and actions, and disrupt bot processing. This issue is fixed in version 4.6.59.

Affected Systems

All installations of PraisonAI earlier than version 4.6.59 that expose the WhatsApp or Linear webhook endpoints are affected. The flaw exists only when WHATSAPP_APP_SECRET or LINEAR_WEBHOOK_SECRET are not set; any deployment that relies on these bots without proper secrets is vulnerable.

Risk and Exploitability

The CVSS score of 8.6 indicates high severity, and the EPSS score is < 1%, indicating a very low yet non‑zero exploitation probability. The flaw is exploitable by any external host that can reach the webhook route. The issue is not listed in CISA KEV, yet the nature of the flaw—remote unauthenticated request forging—implies a high likelihood of abuse, especially in exposed services. Attackers do not need privileges and can abuse the webhook endpoint via HTTP POST with crafted HMAC headers or without any headers at all, thereby bypassing verification entirely.

Generated by OpenCVE AI on September 21, 2026 at 00:09 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade PraisonAI to version 4.6.59 or later to apply the signature‑verification fix.
  • Configure WH for each bot and enforce signature validation on all incoming webhook requests.
  • Disable or remove any unused webhook endpoints to reduce the attack surface.

Generated by OpenCVE AI on September 21, 2026 at 00:09 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-x92v-rpx6-p6cw PraisonAI: Webhook signature verification skipped (fail-open) when secret unset, allowing forged inbound webhooks (WhatsApp & Linear bots)
History

Tue, 15 Sep 2026 07:15:00 +0000

Type Values Removed Values Added
First Time appeared Mervinpraison
Mervinpraison praisonai
Vendors & Products Mervinpraison
Mervinpraison praisonai

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description PraisonAI is a multi-agent teams system. Prior to 4.6.59, the WhatsApp and Linear bot webhook handlers verify HMAC signatures only when WHATSAPP_APP_SECRET or LINEAR_WEBHOOK_SECRET is configured and otherwise parse and dispatch unsigned request bodies. A remote unauthenticated client that reaches the webhook route can forge messages, comments, or agent-session events, impersonate platform users, influence agent prompts and actions, and disrupt bot processing. This issue is fixed in 4.6.59.
Title PraisonAI: Webhook signature verification skipped (fail-open) when secret unset, allowing forged inbound webhooks (WhatsApp & Linear bots)
Weaknesses CWE-345
CWE-347
References
Metrics cvssV3_1

{'score': 8.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Subscriptions

Mervinpraison Praisonai
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-14T18:11:37.800Z

Reserved: 2026-06-24T00:33:17.707Z

Link: CVE-2026-57122

cve-icon Vulnrichment

Updated: 2026-09-14T17:06:09.111Z

cve-icon NVD

Status : Deferred

Published: 2026-09-14T16:17:13.270

Modified: 2026-09-15T14:45:28.563

Link: CVE-2026-57122

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T00:15:06Z

Weaknesses
  • CWE-345

    Insufficient Verification of Data Authenticity

  • CWE-347

    Improper Verification of Cryptographic Signature