Disclosure summary
# AgentMail webhook mode accepts forged unsigned message.received events and invokes agents ## Summary `praisonai` AgentMail webhook mode exposes a public aiohttp webhook endpoint that accepts caller-controlled `message.received` JSON without verifying AgentMail's Svix webhook signatures, then dispatches the forged message into the configured agent session and reply path. ## Technical Details The affected boundary is webhook authenticity. AgentMail's webhook verification documentation says AgentMail delivers webhooks through Svix and includes `svix-id`, `svix-timestamp`, and `svix-signature` headers. Receivers are expected to verify the raw request body with the endpoint signing secret, commonly stored as `AGENTMAIL_WEBHOOK_SECRET`, before trusting the event body. AgentMail's documented verified payload examples route on `event_type`; the forged payload below intentionally uses PraisonAI's accepted handler shape, `type` plus `data`, because that is the shape `_handle_email_webhook()` accepts before any signature verification. `src/praisonai/praisonai/bots/agentmail.py` exposes webhook mode through `AgentMailBot(mode=...)` or a `BotConfig` whose `mode` is `webhook`. In `_start_webho
Source-specific records & product guidance
Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.
GitHub Reviewed Security Advisories · GHSA-7c92-x8vg-4258
Open original source · Updated Oct 07, 2026
PraisonAI: AgentMail webhook mode accepts forged unsigned message.received events and invokes agents
Source severity: HIGH / 0
| Ecosystem | Package | Affected range | First patched |
|---|---|---|---|
| pip | praisonai | 4.6.78 |
Original records & references
- NIST NVD record
- CVE Program record
- github.com — Reviewed advisory
PUBLISHED 2026-10-07T10:07:10-04:00
MODIFIED 2026-10-07T10:07:11-04:00
INGESTED 2026-10-08T12:05:11-04:00