Impact
The vulnerability lies in PraisonAI’s handling of WhatsApp and Linear webhook requests that omits signature verification when the secrets WHATSAPP_APP_SECRET or LINEAR_WEBHOOK_SECRET are not set, allowing unsigned request bodies to be parsed and dispatched. A remote unauthenticated client that reaches the webhook route can forge messages, comments, or agent‑session events, impersonate platform users, influence agent prompts and actions, and disrupt bot processing. This issue is fixed in version 4.6.59.
Affected Systems
All installations of PraisonAI earlier than version 4.6.59 that expose the WhatsApp or Linear webhook endpoints are affected. The flaw exists only when WHATSAPP_APP_SECRET or LINEAR_WEBHOOK_SECRET are not set; any deployment that relies on these bots without proper secrets is vulnerable.
Risk and Exploitability
The CVSS score of 8.6 indicates high severity, and the EPSS score is < 1%, indicating a very low yet non‑zero exploitation probability. The flaw is exploitable by any external host that can reach the webhook route. The issue is not listed in CISA KEV, yet the nature of the flaw—remote unauthenticated request forging—implies a high likelihood of abuse, especially in exposed services. Attackers do not need privileges and can abuse the webhook endpoint via HTTP POST with crafted HMAC headers or without any headers at all, thereby bypassing verification entirely.
OpenCVE Enrichment
Github GHSA