Description
PraisonAI before 4.6.78 fails to verify Svix webhook signatures in AgentMail webhook mode, allowing unauthenticated attackers to forge message.received events. Attackers can send crafted JSON payloads to the webhook endpoint to invoke configured agents with arbitrary sender addresses and message content.
Published: 2026-07-15
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

PraisonAI versions prior to 4.6.78 do not check Svix webhook signatures when the AgentMail webhook mode is enabled. Because of this omission, an unauthenticated attacker can send crafted JSON payloads to the webhook endpoint and cause the system to treat them as legitimate message.received events. The attacker can set any desired sender address and message content, enabling the execution of configured agents with arbitrary inputs.

Affected Systems

The vulnerability affects MervinPraison PraisonAI. All releases before version 4.6.78 are susceptible. No other versions are known to be impacted.

Risk and Exploitability

The CVSS score of 8.8 marks this flaw as high severity, and the EPSS score of less than 1% indicates a low probability of exploitation at present. Because the flaw authentication by simply posting to the exposed webhook endpoint, the potential impact is significant should an attacker succeed. The vulnerability is not currently listed in CISA’s KEV catalog.

Generated by OpenCVE AI on July 31, 2026 at 03:57 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update PraisonAI to version 4.6.78 or later to restore signature verification.
  • If updating is temporarily infeasible, disable the AgentMail webhook integration or restrict the webhook endpoint to trusted IP ranges until the patch is applied.
  • Ensure that no external JSON payloads can reach the webhook endpoint by implementing network segmentation or firewall rules and monitor logs for unexpected agent invocations.

Generated by OpenCVE AI on July 31, 2026 at 03:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 16 Jul 2026 02:45:00 +0000

Type Values Removed Values Added
First Time appeared Mervinpraison
Mervinpraison praisonai
Vendors & Products Mervinpraison
Mervinpraison praisonai

Wed, 15 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 15 Jul 2026 12:00:00 +0000

Type Values Removed Values Added
Description PraisonAI before 4.6.78 fails to verify Svix webhook signatures in AgentMail webhook mode, allowing unauthenticated attackers to forge message.received events. Attackers can send crafted JSON payloads to the webhook endpoint to invoke configured agents with arbitrary sender addresses and message content.
Title PraisonAI before 4.6.78 Missing Webhook Signature Verification
First Time appeared Praison
Praison praisonai
Weaknesses CWE-287
CPEs cpe:2.3:a:praison:praisonai:*:*:*:*:*:*:*:*
Vendors & Products Praison
Praison praisonai
References
Metrics cvssV3_1

{'score': 8.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L'}

cvssV4_0

{'score': 8.8, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:L/SC:N/SI:N/SA:N'}


Subscriptions

Mervinpraison Praisonai
Praison Praisonai
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-07-15T12:39:30.217Z

Reserved: 2026-07-09T14:05:47.928Z

Link: CVE-2026-61436

cve-icon Vulnrichment

Updated: 2026-07-15T12:39:11.031Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T04:00:15Z

Weaknesses