Webhook Message Injection Vulnerability in Xiaobei from TeamWiseFlow
CVE-2026-85667
9.3CRITICAL
What is CVE-2026-85667?
Versions of Xiaobei through 5.5.2 are vulnerable due to a lack of authentication and signature validation on webhook endpoints. This flaw allows unauthorized attackers to send harmful messages into the agent pipeline via the /webhook_worktool handler. Moreover, the vulnerability permits the exploitation of unvalidated media URL fetching, leading to potential server-side request forgery against internal services. This could result in further system compromise or unauthorized access to internal resources.
Affected Version(s)
xiaobei 0 <= 5.5.2
