Executive brief
xiaobei is an AI agent platform designed to automate social media content creation and publishing for small businesses. The vulnerability allows attackers to bypass security controls on webhook endpoints, inject malicious messages into the system's processing pipeline, and exploit the agent to make unauthorized network requests to internal services. This could result in complete compromise of the agent's functionality and access to internal corporate infrastructure.
Technical details
xiaobei through version 5.5.2 fails to implement authentication or signature validation on the /webhook_worktool endpoint handler. The vulnerability combines missing input validation on webhook endpoints with unvalidated media URL fetching, enabling unauthenticated network-accessible attackers to inject arbitrary messages into the agent pipeline. An attacker can directly publish malicious messages to the webhook endpoint without credentials or cryptographic signature verification, and subsequently exploit the agent's media fetching mechanism to perform server-side request forgery (SSRF) attacks against internal services. No authentication is required to trigger the vulnerability; the attack vector is purely network-based with direct HTTP/HTTPS requests to the exposed endpoint.
Affected products
- TeamWiseFlow xiaobei through 5.5.2
Timeline
- 2026-09-04: disclosed
- other: CVE-2026-85667