Webhook Vulnerability in PraisonAI Affecting WhatsApp and Linear Integrations
CVE-2026-57122

8.6HIGH

Key Information:

Status
Vendor
CVE Published:
14 September 2026

What is CVE-2026-57122?

PraisonAI, a multi-agent systems platform, had a security flaw in its webhook handlers for WhatsApp and Linear prior to version 4.6.59. The issue arises as these handlers only verify HMAC signatures when specific secrets are configured. Without this configuration, unsigned request bodies can be processed, allowing unauthorized remote clients to forge messages, impersonate users, and disrupt bot functionalities. This vulnerability has significant implications as it enables malicious interaction with the bot processing system, raising concerns over data integrity and security. The issue has been resolved in version 4.6.59.

Affected Version(s)

PraisonAI < 4.6.59

References

CVSS V3.1

Score:
8.6
Severity:
HIGH
Confidentiality:
Low
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.