DEV Community

CVE Reports
CVE Reports

Posted on Originally published at cvereports.com

CVE-2026-61436: CVE-2026-61436: Missing Webhook Signature Verification in PraisonAI AgentMail Endpoint

CVE-2026-61436: Missing Webhook Signature Verification in PraisonAI AgentMail Endpoint

Vulnerability ID: CVE-2026-61436
CVSS Score: 8.6
Published: 2026-10-07

A critical security flaw exists in PraisonAI before version 4.6.78 when operating in AgentMail webhook mode. The application processes incoming POST requests without checking for cryptographic signatures, allowing unauthenticated attackers to forge emails, spoof identities, and force AI agents to execute unauthorized operations.

TL;DR

Unauthenticated remote attackers can spoof email webhook payloads to PraisonAI endpoints, forcing AI agents to execute unauthorized workflows due to a lack of cryptographic signature verification.


⚠️ Exploit Status: POC

Technical Details

  • CWE ID: CWE-287
  • Attack Vector: Network (Unauthenticated)
  • CVSS v3.1 Score: 8.6 (High)
  • CVSS v4.0 Score: 8.8 (High)
  • EPSS Score: 0.00518
  • EPSS Percentile: 42.17%
  • Exploit Status: Proof-of-Concept (PoC)
  • CISA KEV: Not Listed

Affected Systems

  • PraisonAI deployments utilizing AgentMail configurations
  • praisonai: < 4.6.78 (Fixed in: 4.6.78)

Code Analysis

Commit: 393de39

Fix missing webhook signature verification on AgentMail webhook endpoints

Mitigation Strategies

  • Upgrade the local PraisonAI dependency package to version 4.6.78 or above.
  • Define and enforce the AGENTMAIL_WEBHOOK_SECRET environment variable with a strong, randomly generated alphanumeric string.
  • Implement network-level access control lists (ACLs) to allow webhook traffic exclusively from legitimate service provider IP blocks.

Remediation Steps:

  1. Identify all deployment instances running PraisonAI with AgentMail webhook routes enabled.
  2. Execute 'pip install --upgrade "praisonai>=4.6.78"' to fetch and install the updated build.
  3. Generate a cryptographically secure 32-byte secret key.
  4. Export the secret into the environment configurations as AGENTMAIL_WEBHOOK_SECRET.
  5. Configure the corresponding webhook dispatcher with the exact secret to sign outgoing headers.

References


Read the full report for CVE-2026-61436 on our website for more details including interactive diagrams and full exploit analysis.

Top comments (0)