PatchSiren cyber security CVE debrief
CVE-2026-61436 MervinPraison CVE debrief
CVE-2026-61436 is a vulnerability in PraisonAI's AgentMail webhook mode that allows forged unsigned message.received events to be accepted and agents to be invoked. The affected boundary is webhook authenticity, and the issue arises from the lack of verification of AgentMail's Svix webhook signatures. This vulnerability impacts PraisonAI users who utilize the AgentMail webhook mode, as it could allow attackers to send forged events, potentially leading to unauthorized agent invocation. Defenders should assess their exposure and verify webhook signature verification to prevent potential attacks. The vulnerability is particularly concerning because it allows for the acceptance of una
- Vendor
- MervinPraison
- Product
- praisonai
- CVSS
- HIGH 8.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-07
- Original CVE updated
- 2026-10-07
- Advisory published
- 2026-10-07
- Advisory updated
- 2026-10-07
Who should care
Defenders who use PraisonAI's AgentMail webhook mode should assess their exposure and verify webhook signature verification to prevent potential attacks. This includes operators of PraisonAI's AgentMail webhook mode, platform administrators, vulnerability management teams, and security teams who need to prioritize verifying webhook signature verification in PraisonAI's AgentMail webhook mode and ensure that the AGENTMAIL_WEBHOOK_SECRET is properly stored
Why it matters
CVE-2026-61436 is a vulnerability in PraisonAI's AgentMail webhook mode that allows forged unsigned message.received events to be accepted and agents to be invoked. Defenders should prioritize verifying webhook signature verification to prevent potential attacks.
- Defenders need to verify webhook signature verification to prevent potential attacks
- The vulnerability allows forged unsigned message.received events to be accepted and agents to be invoked
- The issue arises from the lack of verification of AgentMail's Svix webhook signatures
- Defenders should prioritize verifying webhook signature verification in PraisonAI's AgentMail webhook mode
Technical summary
The vulnerability in PraisonAI's AgentMail webhook mode allows forged unsigned message.received events to be accepted and agents to be invoked. This is due to the lack of verification of AgentMail's Svix webhook signatures. The affected boundary is webhook authenticity. The issue arises from the lack of verification of AgentMail's Svix webhook signatures, which are typically delivered through Svix and include svix-id, svix-timestamp, and svix-signature headers. Receivers are expected to verify the raw request body with the endpoint signing secret, commonly stored as AGENTMAIL_WEBHOOK_SECRET, before trusting the event body.
Defensive priority
Defenders should prioritize verifying webhook signature verification in PraisonAI's AgentMail webhook mode and ensure that the AGENTMAIL_WEBHOOK_SECRET is properly stored and used.
Recommended defensive actions
- Verify webhook signature verification in PraisonAI's AgentMail webhook mode
- Ensure that the AGENTMAIL_WEBHOOK_SECRET is properly stored and used
- Review and update PraisonAI to version 4.6.78 or later
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
Evidence notes
The evidence for this vulnerability comes from the PraisonAI source code and the OSV vulnerability database. The issue is related to the lack of verification of webhook signatures in AgentMail webhook mode.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-61436 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-61436
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-61436 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-61436
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
PraisonAI: AgentMail webhook mode accepts forged unsigned message.received events and invokes ag
Unverified legacy reference
URL: https://storage.googleapis.com/osv-vulnerabilities/PyPI/GHSA-7c92-x8vg-4258.json
osv_dev
-
Source reference
Unverified legacy reference
URL: https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-7c92-x8vg-4258
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-62172
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://github.com/MervinPraison/PraisonAI/commit/2a855c470077c7d2e2479a575f7ef7f548d51c33
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://github.com/MervinPraison/PraisonAI/commit/846568c7a5d8ce9e71e56e4c213f027c04909753
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://github.com/MervinPraison/PraisonAI
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://www.vulncheck.com/advisories/praisonai-before-missing-webhook-signature-verification
Supplemental source
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.