PT-2026-60139 · Praisonai · Praisonai

·

CVE-2026-61436

·

Published

2026-07-15

·

Updated

2026-07-15

CVSS v4.0

8.8

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:L/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions PraisonAI versions prior to 4.6.78
Description In AgentMail webhook mode, the software fails to verify Svix webhook signatures. This allows unauthenticated attackers to forge message.received events by sending crafted JSON payloads to the webhook endpoint. Consequently, attackers can invoke configured agents using arbitrary sender addresses and message content.
Recommendations Update PraisonAI to version 4.6.78 or later.

Exploit

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-61436
GHSA-7C92-X8VG-4258

Affected Products

Praisonai