CVE-2026-61436
Deferred Deferred - Pending Action

PraisonAI AgentMail Webhook Signature Bypass

Vulnerability report for CVE-2026-61436, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-15

Last updated on: 2026-07-15

Assigner: VulnCheck

Description

PraisonAI before 4.6.78 fails to verify Svix webhook signatures in AgentMail webhook mode, allowing unauthenticated attackers to forge message.received events. Attackers can send crafted JSON payloads to the webhook endpoint to invoke configured agents with arbitrary sender addresses and message content.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-15
Last Modified
2026-07-15
Generated
2026-08-04
AI Q&A
2026-07-15
EPSS Evaluated
2026-08-03
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
praisonai agentmail to 4.6.78 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-287 When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

PraisonAI before version 4.6.78 fails to verify Svix webhook signatures in AgentMail webhook mode. This allows unauthenticated attackers to forge message.received events by sending crafted JSON payloads to the webhook endpoint. Attackers can then invoke configured agents with arbitrary sender addresses and message content without proper authentication.

Detection Guidance

To detect this vulnerability, check if PraisonAI is running versions before 4.6.78. Inspect webhook endpoints for Svix signature verification. Monitor for unauthorized agent invocations or unexpected message.received events in logs.

Impact Analysis

This vulnerability enables attackers to send unauthorized commands to PraisonAI agents, potentially leading to data breaches, unauthorized model usage, or manipulation of workflows. Attackers could forge emails or messages, impersonate legitimate senders, and trigger unintended agent actions with malicious payloads.

Compliance Impact

This vulnerability could lead to non-compliance with GDPR (data protection) and HIPAA (healthcare data privacy) by enabling unauthorized access to sensitive data, data integrity breaches, and lack of proper authentication for webhook events. Organizations may face legal penalties for failing to protect personal or health information.

Mitigation Strategies

Upgrade PraisonAI to version 4.6.78 or later. Ensure webhook secret is configured and validated. Implement signature verification for Svix webhooks before processing events. Block unsigned or forged message.received events.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-61436. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart