Disclosure summary
## Summary PraisonAI's AgentMail bot, when run in webhook (or hybrid) mode, starts an aiohttp webhook server bound to `0.0.0.0` and processes inbound `message.received` events **without verifying any signature/HMAC and without authentication**. The sender address and message body are taken directly from the attacker-controlled request body, so any network peer can inject messages into the agent with a spoofed sender (bypassing sender allow/block lists) and have the agent process the content and reply to an attacker-chosen address. Sibling bots (`linear.py`, `whatsapp.py`) fail closed when no secret is configured; AgentMail omits the check entirely. Runtime-confirmed; severity Medium. ## Details ### Affected component - Package: `praisonai` 4.6.63. File: `src/praisonai/praisonai/bots/agentmail.py` (`AgentMailBot`, webhook/hybrid mode). ### Vulnerable code / root cause Path: `src/praisonai/praisonai/bots/agentmail.py` Function: `_start_webhook_mode` / `_handle_email_webhook` / `_handle_message` Snippet: ```python # _start_webhook_mode: binds all interfaces self._webhook_site = web.TCPSite(self._webhook_runner, "0.0.0.0", self._webhook_port) # _handle_email_webhook: no signature/HMAC
Source-specific records & product guidance
Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.
GitHub Reviewed Security Advisories · GHSA-qj9c-59p6-8cgx
Open original source · Updated Oct 07, 2026
PraisonAI: AgentMail webhook lacks signature verification, allowing unauthenticated message injection and sender spoofing
Source severity: HIGH / 0
| Ecosystem | Package | Affected range | First patched |
|---|---|---|---|
| pip | praisonai | 4.6.78 |
Original records & references
- NIST NVD record
- CVE Program record
- github.com — Reviewed advisory
PUBLISHED 2026-10-07T10:06:56-04:00
MODIFIED 2026-10-07T10:06:56-04:00
INGESTED 2026-10-08T12:05:11-04:00