PraisonAI: AgentMail webhook lacks signature verification, allowing unauthenticated message injection and sender spoofing
Description
## Summary PraisonAI's AgentMail bot, when run in webhook (or hybrid) mode, starts an aiohttp webhook server bound to `0.0.0.0` and processes inbound `message.received` events **without verifying any signature/HMAC and without authentication**. The sender address and message body are taken directly from the attacker-controlled request body, so any network peer can inject messages into the agent with a spoofed sender (bypassing sender allow/block lists) and have the agent process the content and reply to an attacker-chosen address. Sibling bots (`linear.py`, `whatsapp.py`) fail closed when no secret is configured; AgentMail omits the check entirely. Runtime-confirmed; severity Medium. ## Details ### Affected component - Package: `praisonai` 4.6.63. File: `src/praisonai/praisonai/bots/agentmail.py` (`AgentMailBot`, webhook/hybrid mode). ### Vulnerable code / root cause Path: `src/praisonai/praisonai/bots/agentmail.py` Function: `_start_webhook_mode` / `_handle_email_webhook` / `_handle_message` Snippet: ```python # _start_webhook_mode: binds all interfaces self._webhook_site = web.TCPSite(self._webhook_runner, "0.0.0.0", self._webhook_port) # _handle_email_webhook: no signature/HMAC check, no auth body = await request.json() if body.get("type") != "message.received": return web.Response(status=200, text="OK") asyncio.create_task(self._process_webhook_payload(body)) # dispatch attacker body return web.Response(status=200, text="OK") # _handle_message: agent processes content, replies to attacker-controlled sender response = await self._session.chat(self._agent, sender_id, body, ...) await self.send_message(channel_id=sender_id, ...) ``` Issue: attacker-controlled input is the raw webhook JSON (`from`, `extracted_text`, `subject`). The guard that *should* exist is provider signature verification — there is **none** here (no svix/HMAC, no `webhooks_require_verification()` call). The sink is `self._session.chat(self._agent, ...)` (agent invocation) and `send_message(channel_id=sender_id, ...)` (reply to the spoofed sender). Sibling handlers `src/praisonai/praisonai/bots/linear.py` and `bots/whatsapp.py` call `webhooks_require_verification()` and reject when no secret is set — AgentMail does not, so it fails open. ### Attack flow 1. Operator runs the AgentMail bot in webhook/hybrid mode (documented; binds `0.0.0.0`, default path `/webhook`, default port 8080). 2. Attacker POSTs a crafted `message.received` event with a spoofed `from` and arbitrary `extracted_text`. 3. The agent processes the content; any reply is sent to the attacker-chosen `sender_id`. ### Why existing protection is bypassed There is no protection on this handler: no signature verification, no `webhooks_require_verification()` gate, no auth. Sender allow/block lists are bypassed because `from` is attacker-controlled. ### Security boundary Unauthenticated network peer → agent message pipeline + reply destination. Crosses the bot's inbound trust boundary (provider webhooks are expected to be signed/authenticated). ## Proof of Concept ### Environment Real `AgentMailBot._handle_email_webhook` mounted in a local runtime (`127.0.0.1:18080`); the agent layer is a canary recorder (`/webhook-log`). No real email is sent. Runnable assets: `PraisonAI-Runtime-Repro\runtime-files\`. ### Steps to reproduce 1. `PRAI-03-01-Webhook-Spoofed-Sender`: ```http POST /webhook HTTP/1.1 Host: 127.0.0.1:18080 Content-Type: application/json {"type":"message.received","data":{"from":"[email protected]","extracted_text":"PRAISONAI_WEBHOOK_INJECT_CANARY_7f3a91 ...","subject":"hello","headers":{}}} ``` 2. `PRAI-03-02-Agent-Reached-Response`: `GET /webhook-log`. ### Expected result The webhook should reject unsigned/unauthenticated events; spoofed senders should not reach the agent. ### Actual result - `POST /webhook` → `200 OK` (no auth/signature). - `GET /webhook-log` → `{"reached_agent":[{"sender":"[email protected]","content":"...PRAISONAI_WEBHOOK_INJECT_CANARY_7f3a91...","source":"webhook"}],"count":1}`. ## Impact Unauthenticated message injection into the agent; sender spoofing (access-control bypass); agent reply/exfiltration to an attacker-chosen address; prompt-injection surface; LLM cost abuse. If the agent has dangerous tools, escalation via prompt injection is possible.
CVSS v3.1 base metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:LHigh severity
Band computed from the CVSS base score, not the source's own label — so it means the same thing across every feed.
AV
Network
Attack Vector
AC
Low
Attack Complexity
PR
None
Privileges Required
UI
None
User Interaction
S
Unchanged
Scope
C
Low
Confidentiality
I
Low
Integrity
A
Low
Availability
Affected
- Vendor
- PyPI
- Product
- praisonai
Versions
- pkg:pypi/praisonai < 4.6.78
Stated as the source expressed them.
References
- advisoryOSV GHSA-qj9c-59p6-8cgxhttps://osv.dev/vulnerability/GHSA-qj9c-59p6-8cgx
- otherOSV webhttps://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-qj9c-59p6-8cgx
- advisoryOSV advisoryhttps://nvd.nist.gov/vuln/detail/CVE-2026-61428
- vendorOSV packagehttps://github.com/MervinPraison/PraisonAI
- otherOSV webhttps://www.vulncheck.com/advisories/praisonai-agentmail-before-message-injection-via-webhook
Related threats
same CWE or vendorCVE-2026-83947 — Missing authorization in Azure Event Grid allows an authorized attacker to perform spoofing over a network.
CVE-2026-83947 · 2h ago
CVE-2026-107792 — Jivejdon from commit d58a36b0 through commit ee67a65e contains a missing authorization vulnerability in UpdateThreadToForumAction that allows authe…
CVE-2026-107792 · 3h ago
CVE-2026-107725 — Hazelcast is a unified real-time data platform combining stream processing with a fast data store.
CVE-2026-107725 · 3h ago
CVE-2026-107395 — Indico is an event management system that uses Flask-Multipass, a multi-backend authentication system for Flask.
CVE-2026-107395 · 5h ago
PraisonAI: Prompt-injection defense blocks only when 3+ detector families fire simultaneously; realistic single-vector injections pass through unblocked
CVE-2026-60086 · 6h ago
PraisonAI: API deploy code generator embeds unescaped YAML fields into Python source
CVE-2026-61433 · 6h ago