Webhook Vulnerability in PraisonAI Affecting WhatsApp and Linear Integrations
CVE-2026-57122
8.6HIGH
What is CVE-2026-57122?
PraisonAI, a multi-agent systems platform, had a security flaw in its webhook handlers for WhatsApp and Linear prior to version 4.6.59. The issue arises as these handlers only verify HMAC signatures when specific secrets are configured. Without this configuration, unsigned request bodies can be processed, allowing unauthorized remote clients to forge messages, impersonate users, and disrupt bot functionalities. This vulnerability has significant implications as it enables malicious interaction with the bot processing system, raising concerns over data integrity and security. The issue has been resolved in version 4.6.59.
Affected Version(s)
PraisonAI < 4.6.59
