Impact
PraisonAI versions prior to 4.6.78 do not check Svix webhook signatures when the AgentMail webhook mode is enabled. Because of this omission, an unauthenticated attacker can send crafted JSON payloads to the webhook endpoint and cause the system to treat them as legitimate message.received events. The attacker can set any desired sender address and message content, enabling the execution of configured agents with arbitrary inputs.
Affected Systems
The vulnerability affects MervinPraison PraisonAI. All releases before version 4.6.78 are susceptible. No other versions are known to be impacted.
Risk and Exploitability
The CVSS score of 8.8 marks this flaw as high severity, and the EPSS score of less than 1% indicates a low probability of exploitation at present. Because the flaw authentication by simply posting to the exposed webhook endpoint, the potential impact is significant should an attacker succeed. The vulnerability is not currently listed in CISA’s KEV catalog.
OpenCVE Enrichment