Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
PraisonAI AgentMail before 4.6.78 Message Injection via Webhook
Vulnerability Description
PraisonAI AgentMail versions before 4.6.78 lack signature verification in webhook mode, allowing unauthenticated attackers to inject messages with spoofed sender addresses. Attackers can POST crafted message.received events to the webhook endpoint to inject arbitrary content into the agent and trigger replies to attacker-controlled addresses, bypassing sender allow/block lists.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Vulnerability Type
使用欺骗进行的认证绕过
Vulnerability Title
Mervin Praison PraisonAI 授权问题漏洞
Vulnerability Description
Mervin Praison PraisonAI是Mervin Praison个人开发者开源的一个低代码多智能体协作框架。 Mervin Praison PraisonAI 4.6.78之前版本存在授权问题漏洞,该漏洞源于webhook模式缺少签名验证,可能导致未经身份验证的攻击者POST特制的message.received事件到webhook端点,注入任意内容到agent并触发向攻击者控制的地址回复,绕过发送者允许/阻止列表。
CVSS Information
N/A
Vulnerability Type
N/A