Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4183 articles · 197350 vulns · 37/41 feeds (7d)
← Back to list
8.6
CVE-2026-61436PATCHED
mervinpraison · praisonai

PraisonAI before 4.6.78 Missing Webhook Signature Verification

Description

PraisonAI before 4.6.78 fails to verify Svix webhook signatures in AgentMail webhook mode, allowing unauthenticated attackers to forge message.received events. Attackers can send crafted JSON payloads to the webhook endpoint to invoke configured agents with arbitrary sender addresses and message content.

Affected Products

VendorProductVersions
mervinpraisonpraisonai0

References

  • https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-7c92-x8vg-4258(vendor-advisory)
  • https://github.com/MervinPraison/PraisonAI/commit/846568c7a5d8ce9e71e56e4c213f027c04909753(patch)
  • https://github.com/MervinPraison/PraisonAI/commit/2a855c470077c7d2e2479a575f7ef7f548d51c33(patch)
  • https://www.vulncheck.com/advisories/praisonai-before-missing-webhook-signature-verification(third-party-advisory)

Related News (1 articles)

Tier C
VulDB41d ago
CVE-2026-61436 | MervinPraison PraisonAI up to 4.6.77 AgentMail Webhook Mode sender/content data authenticity
→ No new info (linked only)
CVSS 3.18.6 NONE
CISA KEV❌ No
Actively exploited❌ No
Patch available
4.6.78
CWECWE-287
PublishedJul 15, 2026
Last enriched41d agov2
Trending Score1
Source articles1
Independent1
Info Completeness8/14
Missing: cvss, epss, kev, exploit, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

HIGHCVE-2026-55533
PraisonAI: Authentication fail-open in Recipe server allows unauthenticated access when API key or JWT auth is configured without a secret
Trending: 44
HIGHCVE-2026-55538
PraisonAI: [Auth Bypass] `praisonai serve agents --api-key` is silently ignored — agent-invocation routes (`POST /agents`, `POST /agents/{agent_name}`) run unauthenticated
Trending: 44
HIGHCVE-2026-55525
PraisonAI: SSRF via redirect-following in praisonaiagents web_crawl
Trending: 44
HIGHCVE-2026-55532
PraisonAI: Origin-validation bypass (startswith prefix match) enables unauthenticated cross-site request forgery against the PraisonAI MCP HTTP server
Trending: 35
HIGHCVE-2026-55537
PraisonAI: Webhook SSRF via DNS fail-open in `JobSubmitRequest.validate_webhook_url()` — bypass of CVE-2026-40114
Trending: 35

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jul 15, 2026
Discovered by ZDM
Jul 15, 2026
Updated: description, severity
Jul 15, 2026
Patch Available
Jul 15, 2026

Version History

v2
Last enriched 41d ago
v2Tier C41d ago

Updated severity to CRITICAL, corrected exploit availability, and provided a more detailed description of the vulnerability.

descriptionseverity
via VulDB
v141d ago

Initial creation