Executive brief
PraisonAI is a multi-agent automation system that processes messages from WhatsApp and Linear. When the corresponding API secrets are not configured, the webhook handlers skip signature verification and accept unsigned requests. An attacker can send forged messages to impersonate users, manipulate bot behavior, or disrupt service without needing any credentials or authentication.
Technical details
The vulnerability is a conditional authentication bypass in webhook signature verification. The WhatsApp and Linear bot webhook handlers check HMAC signatures only when their respective environment variables (WHATSAPP_APP_SECRET and LINEAR_WEBHOOK_SECRET) are set; if these are absent, the handlers parse and dispatch unsigned request bodies directly. An unauthenticated remote attacker with network access to the webhook endpoints can forge webhook requests to forge messages, comments, or agent-session events, impersonate platform users, and influence agent prompts and actions. The issue was resolved in version 4.6.59 by hardening input validation and access controls.
Affected products
- MervinPraison PraisonAI prior to 4.6.59
Timeline
- 2026-09-14: disclosed
- 2026-06-13: patched