CVE-2026-61436
HIGHPraisonAI before 4.6.78 Missing Webhook Signature Verification
Title source: cnaDescription
PraisonAI before 4.6.78 fails to verify Svix webhook signatures in AgentMail webhook mode, allowing unauthenticated attackers to forge message.received events. Attackers can send crafted JSON payloads to the webhook endpoint to invoke configured agents with arbitrary sender addresses and message content.
References (4)
Core 4
Core References
Vendor Advisory vendor-advisory
GitHub Security Advisory (GHSA-7c92-x8vg-4258)
https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-7c92-x8vg-4258
Patch patch
https://github.com/MervinPraison/PraisonAI/commit/846568c7a5d8ce9e71e56e4c213f027c04909753
Patch patch
https://github.com/MervinPraison/PraisonAI/commit/2a855c470077c7d2e2479a575f7ef7f548d51c33
Third Party Advisory third-party-advisory
VulnCheck Advisory: PraisonAI before 4.6.78 Missing Webhook Signature Verification
https://www.vulncheck.com/advisories/praisonai-before-missing-webhook-signature-verification
Scores
CVSS v3
8.6
EPSS
0.0029
EPSS Percentile
21.3%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-287
Status
published
Products (2)
MervinPraison/PraisonAI
< 4.6.78
MervinPraison/PraisonAI
4.6.78
Published
Jul 15, 2026
Tracked Since
Jul 15, 2026