CVE-2026-61428 MEDIUM

CVE-2026-61428: PraisonAI AgentMail before 4.6.78 Message Injection via Webhook

Vendor Mervinpraison
Product PraisonAI
Weakness CWE-290
Published July 11, 2026
Last update July 11, 2026

CVSS base score

6.9/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N

What the vulnerability does

01Description

PraisonAI AgentMail versions before 4.6.78 lack signature verification in webhook mode, allowing unauthenticated attackers to inject messages with spoofed sender addresses. Attackers can POST crafted message.received events to the webhook endpoint to inject arbitrary content into the agent and trigger replies to attacker-controlled addresses, bypassing sender allow/block lists.

Key dates

02Disclosure timeline

July 11, 2026 CVE published

Related vulnerabilities

04Related CVE