---
id: CVE-2026-61428
title: >-
  PraisonAI AgentMail versions before 4.6.78 lack signature verification in
  webhook mode, allowing unauthenticated attackers to inject messages with
  spoofed sender addresses
summary: >-
  PraisonAI AgentMail versions before 4.6.78 lack signature verification in
  webhook mode, allowing unauthenticated attackers to inject messages with
  spoofed sender addresses. Attackers can POST crafted message.received events
  to the webhoo…
severity: high
cvss: 7.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L'
cwe:
  - CWE-290
published: '2026-07-11'
updated: '2026-07-11'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-61428'
references:
  - url: >-
      https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-qj9c-59p6-8cgx
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/praisonai-agentmail-before-message-injection-via-webhook
    label: disclosure@vulncheck.com
tags:
  - nvd
ingestedAt: '2026-07-11T23:16:21.315Z'
epss: 0.00373
epssPercentile: 0.28406
---

## Overview

PraisonAI AgentMail versions before 4.6.78 lack signature verification in webhook mode, allowing unauthenticated attackers to inject messages with spoofed sender addresses. Attackers can POST crafted message.received events to the webhook endpoint to inject arbitrary content into the agent and trigger replies to attacker-controlled addresses, bypassing sender allow/block lists.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
