CVE-2026-61428

HIGH

PraisonAI AgentMail before 4.6.78 Message Injection via Webhook

Title source: cna
STIX 2.1

Description

PraisonAI AgentMail versions before 4.6.78 lack signature verification in webhook mode, allowing unauthenticated attackers to inject messages with spoofed sender addresses. Attackers can POST crafted message.received events to the webhook endpoint to inject arbitrary content into the agent and trigger replies to attacker-controlled addresses, bypassing sender allow/block lists.

References (2)

Core 2
Core References
Vendor Advisory vendor-advisory
GitHub Security Advisory (GHSA-qj9c-59p6-8cgx)
https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-qj9c-59p6-8cgx
Third Party Advisory third-party-advisory
VulnCheck Advisory: PraisonAI AgentMail before 4.6.78 Message Injection via Webhook
https://www.vulncheck.com/advisories/praisonai-agentmail-before-message-injection-via-webhook

Scores

CVSS v3 7.3
EPSS 0.0025
EPSS Percentile 15.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-290
Status published
Products (2)
MervinPraison/PraisonAI < 4.6.78
MervinPraison/PraisonAI 4.6.78
Published Jul 11, 2026
Tracked Since Jul 11, 2026