{"id":"GHSA-m64w-vfg6-36ph","title":"Duplicate Advisory: PraisonAI: AgentMail webhook mode accepts forged unsigned message.received events and invokes agents","summary":"Duplicate Advisory: PraisonAI: AgentMail webhook mode accepts forged unsigned message.received events and invokes agents","severity":"high","cvss":8.6,"cwe":["CWE-287"],"vendor":"praisonai","product":"praisonai","ecosystem":"pip","affected":["praisonai <= 4.6.77"],"published":"2026-07-15","updated":"2026-10-07","sourceUpdated":"2026-10-07T14:06:38Z","source":"GHSA","sourceUrl":"https://github.com/advisories/GHSA-m64w-vfg6-36ph","references":[{"url":"https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-7c92-x8vg-4258"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-61436"},{"url":"https://github.com/MervinPraison/PraisonAI/commit/2a855c470077c7d2e2479a575f7ef7f548d51c33"},{"url":"https://github.com/MervinPraison/PraisonAI/commit/846568c7a5d8ce9e71e56e4c213f027c04909753"},{"url":"https://www.vulncheck.com/advisories/praisonai-before-missing-webhook-signature-verification"},{"url":"https://github.com/advisories/GHSA-m64w-vfg6-36ph"}],"tags":["ghsa","pip"],"ingestedAt":"2026-10-07T14:33:21.959Z","slug":"GHSA-m64w-vfg6-36ph","body":"## Overview\n\n### Duplicate Advisory\nThis advisory has been withdrawn because it is a duplicate of GHSA-7c92-x8vg-4258. This link is maintained to preserve external references.\n\n### Original Description\nPraisonAI before 4.6.78 fails to verify Svix webhook signatures in AgentMail webhook mode, allowing unauthenticated attackers to forge message.received events. Attackers can send crafted JSON payloads to the webhook endpoint to invoke configured agents with arbitrary sender addresses and message content.\n\n## Affected packages\n\n- `praisonai <= 4.6.77`\n\n## Remediation\n\nRefer to the advisory for the patched release.","depth":"twilight","depthScore":47,"depthScoreParts":{"impact":47.3,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}