{"success":true,"data":{"threats":[{"id":"dfe7ffbd-dbd8-431d-9e3b-d9ffeda91b85","slug":"cve-2026-61428","externalId":"GHSA-qj9c-59p6-8cgx","source":"OSV","sourceType":"ghsa","type":"vulnerability","title":"PraisonAI: AgentMail webhook lacks signature verification, allowing unauthenticated message injection and sender spoofing","description":"## Summary\n\nPraisonAI's AgentMail bot, when run in webhook (or hybrid) mode, starts an aiohttp webhook server bound to `0.0.0.0` and processes inbound `message.received` events **without verifying any signature/HMAC and without authentication**. The sender address and message body are taken directly from the attacker-controlled request body, so any network peer can inject messages into the agent with a spoofed sender (bypassing sender allow/block lists) and have the agent process the content and reply to an attacker-chosen address. Sibling bots (`linear.py`, `whatsapp.py`) fail closed when no secret is configured; AgentMail omits the check entirely. Runtime-confirmed; severity Medium.\n\n## Details\n\n### Affected component\n- Package: `praisonai` 4.6.63. File: `src/praisonai/praisonai/bots/agentmail.py` (`AgentMailBot`, webhook/hybrid mode).\n\n### Vulnerable code / root cause\n\nPath:\n`src/praisonai/praisonai/bots/agentmail.py`\n\nFunction:\n`_start_webhook_mode` / `_handle_email_webhook` / `_handle_message`\n\nSnippet:\n```python\n# _start_webhook_mode: binds all interfaces\nself._webhook_site = web.TCPSite(self._webhook_runner, \"0.0.0.0\", self._webhook_port)\n\n# _handle_email_webhook: no signature/HMAC check, no auth\nbody = await request.json()\nif body.get(\"type\") != \"message.received\":\n    return web.Response(status=200, text=\"OK\")\nasyncio.create_task(self._process_webhook_payload(body))   # dispatch attacker body\nreturn web.Response(status=200, text=\"OK\")\n\n# _handle_message: agent processes content, replies to attacker-controlled sender\nresponse = await self._session.chat(self._agent, sender_id, body, ...)\nawait self.send_message(channel_id=sender_id, ...)\n```\nIssue: attacker-controlled input is the raw webhook JSON (`from`, `extracted_text`, `subject`). The guard that *should* exist is provider signature verification — there is **none** here (no svix/HMAC, no `webhooks_require_verification()` call). The sink is `self._session.chat(self._agent, ...)` (agent invocation) and `send_message(channel_id=sender_id, ...)` (reply to the spoofed sender). Sibling handlers `src/praisonai/praisonai/bots/linear.py` and `bots/whatsapp.py` call `webhooks_require_verification()` and reject when no secret is set — AgentMail does not, so it fails open.\n\n### Attack flow\n1. Operator runs the AgentMail bot in webhook/hybrid mode (documented; binds `0.0.0.0`, default path `/webhook`, default port 8080).\n2. Attacker POSTs a crafted `message.received` event with a spoofed `from` and arbitrary `extracted_text`.\n3. The agent processes the content; any reply is sent to the attacker-chosen `sender_id`.\n\n### Why existing protection is bypassed\nThere is no protection on this handler: no signature verification, no `webhooks_require_verification()` gate, no auth. Sender allow/block lists are bypassed because `from` is attacker-controlled.\n\n### Security boundary\nUnauthenticated network peer → agent message pipeline + reply destination. Crosses the bot's inbound trust boundary (provider webhooks are expected to be signed/authenticated).\n\n## Proof of Concept\n\n### Environment\nReal `AgentMailBot._handle_email_webhook` mounted in a local runtime (`127.0.0.1:18080`); the agent layer is a canary recorder (`/webhook-log`). No real email is sent. Runnable assets: `PraisonAI-Runtime-Repro\\runtime-files\\`.\n\n### Steps to reproduce\n1. `PRAI-03-01-Webhook-Spoofed-Sender`:\n```http\nPOST /webhook HTTP/1.1\nHost: 127.0.0.1:18080\nContent-Type: application/json\n\n{\"type\":\"message.received\",\"data\":{\"from\":\"attacker@evil.example\",\"extracted_text\":\"PRAISONAI_WEBHOOK_INJECT_CANARY_7f3a91 ...\",\"subject\":\"hello\",\"headers\":{}}}\n```\n2. `PRAI-03-02-Agent-Reached-Response`: `GET /webhook-log`.\n\n### Expected result\nThe webhook should reject unsigned/unauthenticated events; spoofed senders should not reach the agent.\n\n### Actual result\n- `POST /webhook` → `200 OK` (no auth/signature).\n- `GET /webhook-log` → `{\"reached_agent\":[{\"sender\":\"attacker@evil.example\",\"content\":\"...PRAISONAI_WEBHOOK_INJECT_CANARY_7f3a91...\",\"source\":\"webhook\"}],\"count\":1}`.\n\n## Impact\nUnauthenticated message injection into the agent; sender spoofing (access-control bypass); agent reply/exfiltration to an attacker-chosen address; prompt-injection surface; LLM cost abuse. If the agent has dangerous tools, escalation via prompt injection is possible.","cveId":"CVE-2026-61428","cvssScore":null,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","severity":"high","vendor":"PyPI","product":"praisonai","affectedVersions":["pkg:pypi/praisonai < 4.6.78"],"cwes":["CWE-290","CWE-345","CWE-862"],"tags":["osv","osv:ghsa-qj9c-59p6-8cgx","ecosystem:pypi"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://osv.dev/vulnerability/GHSA-qj9c-59p6-8cgx","type":"advisory","title":"OSV GHSA-qj9c-59p6-8cgx"},{"url":"https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-qj9c-59p6-8cgx","type":"other","title":"OSV web"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-61428","type":"advisory","title":"OSV advisory"},{"url":"https://github.com/MervinPraison/PraisonAI","type":"vendor","title":"OSV package"},{"url":"https://www.vulncheck.com/advisories/praisonai-agentmail-before-message-injection-via-webhook","type":"other","title":"OSV web"}],"epssScore":0.00373,"epssPercentile":0.29118,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-07T14:06:56.000Z","addedAt":"2026-10-07T18:42:45.500Z","updatedAt":"2026-10-07T18:42:45.500Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-61428","note":"may still be awaiting NVD analysis"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-61428","note":"authoritative record"},{"label":"GitHub Advisory","url":"https://github.com/advisories/GHSA-qj9c-59p6-8cgx"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-qj9c-59p6-8cgx"}]}],"pagination":{"page":1,"limit":20,"total":1,"totalPages":1,"hasNext":false,"hasPrev":false}},"meta":{"apiVersion":"v1","requestedAt":"2026-10-09T02:41:48.881Z","durationMs":13,"filters":{"search":null,"severity":[],"type":[],"country":[],"tag":["osv:ghsa-qj9c-59p6-8cgx"],"cwe":[],"vendor":null,"product":null,"cve":null,"source":[],"days":null,"publishedAfter":null,"publishedBefore":null,"minCvss":null,"maxCvss":null,"minEpss":null,"knownExploited":null,"hasPatch":null,"hasNucleiTemplate":null},"sort":"newest","unknownParams":[],"warnings":[]}}