PT-2026-60139 · Praisonai · Praisonai
CVSS v4.0
8.8
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:L/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
PraisonAI versions prior to 4.6.78
Description
In AgentMail webhook mode, the software fails to verify Svix webhook signatures. This allows unauthenticated attackers to forge
message.received events by sending crafted JSON payloads to the webhook endpoint. Consequently, attackers can invoke configured agents using arbitrary sender addresses and message content.Recommendations
Update PraisonAI to version 4.6.78 or later.
Exploit
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Praisonai