---
id: CVE-2026-85667
title: >-
  xiaobei through 5.5.2 fails to implement authentication or signature
  validation on webhook endpoints, allowing unauthenticated attackers to inject
  arbitrary messages into the agent pipeline
summary: >-
  xiaobei through 5.5.2 fails to implement authentication or signature
  validation on webhook endpoints, allowing unauthenticated attackers to inject
  arbitrary messages into the agent pipeline. Attackers can publish malicious
  messages via t…
severity: critical
cvss: 9.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'
cwe:
  - CWE-306
vendor: TeamWiseFlow
product: xiaobei
affected:
  - xiaobei <= 5.5.2
published: '2026-09-04'
updated: '2026-09-10'
sourceUpdated: '2026-09-10T15:53:23.707'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-85667'
references:
  - url: 'https://github.com/TeamWiseFlow/xiaobei'
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/TeamWiseFlow/xiaobei/blob/v5.5.2/awada/awada-server/src/routes/webhook-worktool.ts
    label: disclosure@vulncheck.com
  - url: 'https://github.com/TeamWiseFlow/xiaobei/issues/440'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/xiaobei-through-5.5.2-unauthenticated-webhook-message-injection
    label: disclosure@vulncheck.com
  - url: 'https://github.com/TeamWiseFlow/xiaobei/issues/440'
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
  - cve.org
  - exploit-available
epss: 0.00383
epssPercentile: 0.32255
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'yes'
  technicalImpact: total
  timestamp: '2026-09-08T17:04:28.746442Z'
ingestedAt: '2026-09-08T19:08:49.592Z'
---

## Overview

xiaobei through 5.5.2 fails to implement authentication or signature validation on webhook endpoints, allowing unauthenticated attackers to inject arbitrary messages into the agent pipeline. Attackers can publish malicious messages via the /webhook_worktool handler and exploit unvalidated media URL fetching to perform server-side request forgery against internal services.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
