---
id: GHSA-m64w-vfg6-36ph
title: >-
  Duplicate Advisory: PraisonAI: AgentMail webhook mode accepts forged unsigned
  message.received events and invokes agents
summary: >-
  Duplicate Advisory: PraisonAI: AgentMail webhook mode accepts forged unsigned
  message.received events and invokes agents
severity: high
cvss: 8.6
cwe:
  - CWE-287
vendor: praisonai
product: praisonai
ecosystem: pip
affected:
  - praisonai <= 4.6.77
published: '2026-07-15'
updated: '2026-10-07'
sourceUpdated: '2026-10-07T14:06:38Z'
source: GHSA
sourceUrl: 'https://github.com/advisories/GHSA-m64w-vfg6-36ph'
references:
  - url: >-
      https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-7c92-x8vg-4258
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-61436'
  - url: >-
      https://github.com/MervinPraison/PraisonAI/commit/2a855c470077c7d2e2479a575f7ef7f548d51c33
  - url: >-
      https://github.com/MervinPraison/PraisonAI/commit/846568c7a5d8ce9e71e56e4c213f027c04909753
  - url: >-
      https://www.vulncheck.com/advisories/praisonai-before-missing-webhook-signature-verification
  - url: 'https://github.com/advisories/GHSA-m64w-vfg6-36ph'
tags:
  - ghsa
  - pip
ingestedAt: '2026-10-07T14:33:21.959Z'
---

## Overview

### Duplicate Advisory
This advisory has been withdrawn because it is a duplicate of GHSA-7c92-x8vg-4258. This link is maintained to preserve external references.

### Original Description
PraisonAI before 4.6.78 fails to verify Svix webhook signatures in AgentMail webhook mode, allowing unauthenticated attackers to forge message.received events. Attackers can send crafted JSON payloads to the webhook endpoint to invoke configured agents with arbitrary sender addresses and message content.

## Affected packages

- `praisonai <= 4.6.77`

## Remediation

Refer to the advisory for the patched release.
