CVE-2026-57122High· 8.6▾ TwilightPraisonAI is a multi-agent teams system. Prior to 4.6.59, the WhatsApp and Linear bot webhook handlers verify HMAC signatures only when WHATSAPP_APP_SECRET or LINEAR_WEBHOOK_SECRET is configured and otherwise parse and dispatch unsigned …
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 47.3 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Exploit-prediction probability, daily snapshots since Sep 15.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.1%
PraisonAI is a multi-agent teams system. Prior to 4.6.59, the WhatsApp and Linear bot webhook handlers verify HMAC signatures only when WHATSAPP_APP_SECRET or LINEAR_WEBHOOK_SECRET is configured and otherwise parse and dispatch unsigned request bodies. A remote unauthenticated client that reaches the webhook route can forge messages, comments, or agent-session events, impersonate platform users, influence agent prompts and actions, and disrupt bot processing. This issue is fixed in 4.6.59.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Affected packages:
praisonai < 4.6.59Patched in:
praisonai 4.6.59Connected by shared product, vendor, weakness, or advisory.
CVE-2026-57112High· 8.3PraisonAI is a multi-agent teams system
CVE-2026-57124Critical· 9.8PraisonAI is a multi-agent teams system
CVE-2026-57119High· 7.5PraisonAI is a multi-agent teams system
CVE-2026-57125Critical· 9.8PraisonAI is a multi-agent teams system
CVE-2026-57123Critical· 9.8PraisonAI is a multi-agent teams system
CVE-2026-57120Medium· 6.5PraisonAI is a multi-agent teams system