PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-61436 MervinPraison CVE debrief

CVE-2026-61436 is a vulnerability in PraisonAI's AgentMail webhook mode that allows forged unsigned message.received events to be accepted and agents to be invoked. The affected boundary is webhook authenticity, and the issue arises from the lack of verification of AgentMail's Svix webhook signatures. This vulnerability impacts PraisonAI users who utilize the AgentMail webhook mode, as it could allow attackers to send forged events, potentially leading to unauthorized agent invocation. Defenders should assess their exposure and verify webhook signature verification to prevent potential attacks. The vulnerability is particularly concerning because it allows for the acceptance of una

Vendor
MervinPraison
Product
praisonai
CVSS
HIGH 8.8
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-07
Original CVE updated
2026-10-07
Advisory published
2026-10-07
Advisory updated
2026-10-07

Who should care

Defenders who use PraisonAI's AgentMail webhook mode should assess their exposure and verify webhook signature verification to prevent potential attacks. This includes operators of PraisonAI's AgentMail webhook mode, platform administrators, vulnerability management teams, and security teams who need to prioritize verifying webhook signature verification in PraisonAI's AgentMail webhook mode and ensure that the AGENTMAIL_WEBHOOK_SECRET is properly stored

Why it matters

CVE-2026-61436 is a vulnerability in PraisonAI's AgentMail webhook mode that allows forged unsigned message.received events to be accepted and agents to be invoked. Defenders should prioritize verifying webhook signature verification to prevent potential attacks.

  • Defenders need to verify webhook signature verification to prevent potential attacks
  • The vulnerability allows forged unsigned message.received events to be accepted and agents to be invoked
  • The issue arises from the lack of verification of AgentMail's Svix webhook signatures
  • Defenders should prioritize verifying webhook signature verification in PraisonAI's AgentMail webhook mode

Technical summary

The vulnerability in PraisonAI's AgentMail webhook mode allows forged unsigned message.received events to be accepted and agents to be invoked. This is due to the lack of verification of AgentMail's Svix webhook signatures. The affected boundary is webhook authenticity. The issue arises from the lack of verification of AgentMail's Svix webhook signatures, which are typically delivered through Svix and include svix-id, svix-timestamp, and svix-signature headers. Receivers are expected to verify the raw request body with the endpoint signing secret, commonly stored as AGENTMAIL_WEBHOOK_SECRET, before trusting the event body.

Defensive priority

Defenders should prioritize verifying webhook signature verification in PraisonAI's AgentMail webhook mode and ensure that the AGENTMAIL_WEBHOOK_SECRET is properly stored and used.

Recommended defensive actions

  • Verify webhook signature verification in PraisonAI's AgentMail webhook mode
  • Ensure that the AGENTMAIL_WEBHOOK_SECRET is properly stored and used
  • Review and update PraisonAI to version 4.6.78 or later
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review

Evidence notes

The evidence for this vulnerability comes from the PraisonAI source code and the OSV vulnerability database. The issue is related to the lack of verification of webhook signatures in AgentMail webhook mode.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-61436 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-61436

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-61436 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-61436

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • PraisonAI: AgentMail webhook mode accepts forged unsigned message.received events and invokes ag

    Unverified legacy reference

    URL: https://storage.googleapis.com/osv-vulnerabilities/PyPI/GHSA-7c92-x8vg-4258.json

    osv_dev

  • Source reference

    Unverified legacy reference

    URL: https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-7c92-x8vg-4258

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-62172

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://github.com/MervinPraison/PraisonAI/commit/2a855c470077c7d2e2479a575f7ef7f548d51c33

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://github.com/MervinPraison/PraisonAI/commit/846568c7a5d8ce9e71e56e4c213f027c04909753

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://github.com/MervinPraison/PraisonAI

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://www.vulncheck.com/advisories/praisonai-before-missing-webhook-signature-verification

    Supplemental source

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.