Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4mp6-8448-9vgv

Опубликовано: 11 июл. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 6.9
CVSS3: 7.3

Описание

PraisonAI AgentMail versions before 4.6.78 lack signature verification in webhook mode, allowing unauthenticated attackers to inject messages with spoofed sender addresses. Attackers can POST crafted message.received events to the webhook endpoint to inject arbitrary content into the agent and trigger replies to attacker-controlled addresses, bypassing sender allow/block lists.

PraisonAI AgentMail versions before 4.6.78 lack signature verification in webhook mode, allowing unauthenticated attackers to inject messages with spoofed sender addresses. Attackers can POST crafted message.received events to the webhook endpoint to inject arbitrary content into the agent and trigger replies to attacker-controlled addresses, bypassing sender allow/block lists.

EPSS

Процентиль: 16%
0.00246
Низкий

6.9 Medium

CVSS4

7.3 High

CVSS3

Дефекты

CWE-290

Связанные уязвимости

CVSS3: 7.3
nvd
около 1 месяца назад

PraisonAI AgentMail versions before 4.6.78 lack signature verification in webhook mode, allowing unauthenticated attackers to inject messages with spoofed sender addresses. Attackers can POST crafted message.received events to the webhook endpoint to inject arbitrary content into the agent and trigger replies to attacker-controlled addresses, bypassing sender allow/block lists.

EPSS

Процентиль: 16%
0.00246
Низкий

6.9 Medium

CVSS4

7.3 High

CVSS3

Дефекты

CWE-290