Impact
PraisonAI AgentMail versions before 4.6.78 do not verify signatures in webhook mode, so any user can POST crafted message.received events. An attacker can inject arbitrary message content that the agent will send to the specified address, bypassing the sender allow and block lists. The vulnerability enables the attacker to spoof a sender address, cause automated replies, and potentially launch phishing or spam campaigns. This flaw is categorized as CWE‑290.
Affected Systems
MervinPraison’s PraisonAI AgentMail product is affected for all versions prior to 4.6.78. No unaffected older versions are identified.
Risk and Exploitability
The CVSS score of 6.9 indicates medium severity, and the EPSS score of < 1% indicates a very low exploitation probability. The vulnerability is not listed in CISA KEV. An attacker can exploit the flaw from an external network without any authentication, making the attack vector easy to reach. Because the flaw allows messages to be sent to arbitrary addresses, the potential impact spans confidentiality of email content and reputation of the sender domain.
OpenCVE Enrichment