Impact
The vulnerability is an unauthenticated injection that allows an attacker to send crafted messages to the /webhook_worktool endpoint, which are then processed by Xiaobei's agent pipeline. Because the server also downloads user‑supplied media URLs without validation, the injection can trigger server‑side request forgery against internal services, potentially exposing or modifying sensitive data or enabling further compromise. The flaw effectively enables an attacker to inject arbitrary content and manipulate internal requests, which could lead to remote code execution within the underlying agent services if an internal system is compromised.
Affected Systems
All releases of TeamWiseFlow Xiaobei up to and including version 5.5.2 are affected.
Risk and Exploitability
The CVSS score of 9.3 reflects high severity. Attackers need only craft an unauthenticated HTTP request to the exposed webhook endpoint; no authentication or signature validation is required. The lack of authentication and validation makes exploitation trivial. No EPSS score is available, but the mechanics and severity indicate it may be abused by motivated adversaries. The vulnerability is not listed in the CISA KEV catalog, but due to the potential for internal compromise it warrants immediate attention.
OpenCVE Enrichment