Webhook Signature Verification Bypass in Appwrite Templates by Appwrite
CVE-2026-72861

6.9MEDIUM

Key Information:

Vendor

Appwrite

Status
Vendor
CVE Published:
20 August 2026

What is CVE-2026-72861?

A vulnerability exists in Appwrite Templates' GitHub issue bot due to improper verification of the GitHub webhook signature. The verifyWebhook function's logic incorrectly allows unauthenticated requests without a valid X-Hub-Signature-256 header to succeed. This flaw enables attackers to post unauthorized comments on any repository and issue using the configured GITHUB_TOKEN. By exploiting this vulnerability, an attacker can manipulate the function to execute actions that should otherwise be restricted, posing significant risks to the integrity of the repositories involved.

Affected Version(s)

templates 0 <= 1.1.2

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

potdf-bl4ck-570rm
.