Unauthenticated Webhook Vulnerability in Plunk by UsePlunk
CVE-2026-42193
9.1CRITICAL
What is CVE-2026-42193?
Plunk, an open-source email platform leveraging Amazon Simple Email Service (SES), contains a vulnerability in its /webhooks/sns endpoint that permits unauthenticated requests. Prior to version 0.9.0, the absence of verification for Amazon SNS signatures, certificates, and topic ARNs enabled unauthorized users to spoof valid webhook notifications. This vulnerability potentially allows attackers to manipulate workflow automations, unsubscribe contacts, and skew email delivery metrics, thus risking significant financial implications through billing credit depletion. The issue has been rectified in version 0.9.0.
Affected Version(s)
plunk < 0.9.0
