PT-2026-85560 · Teamwiseflow · Xiaobei

·

CVE-2026-85667

·

Publicado

2026-09-04

·

Atualizado

2026-09-04

CVSS v3.1

9.1

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
xiaobei through 5.5.2 fails to implement authentication or signature validation on webhook endpoints, allowing unauthenticated attackers to inject arbitrary messages into the agent pipeline. Attackers can publish malicious messages via the /webhook worktool handler and exploit unvalidated media URL fetching to perform server-side request forgery against internal services.

Correção

Missing Authentication

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-85667

Produtos afetados

Xiaobei