CVE-2026-85667
xiaobei through 5.5.2 fails to implement authentication or signature validation on webhook endpoints, allowing unauthenticated attackers to inject arbitrary messages into the agent pipeline. Attackers can publish malicious messages via the /webhook_worktool handler and exploit unvalidated media URL fetching to perform server-side request forgery against internal services.
Słabość
xiaobei through 5.5.2 fails to implement authentication or signature validation on webhook endpoints, allowing unauthenticated attackers to inject arbitrary messages into the agent pipeline. Attackers can publish malicious messages via the /webhook_worktool handler and exploit unvalidated media URL fetching to perform server-side request forgery against internal services.
Źródła
- https://github.com/TeamWiseFlow/xiaobei
- https://github.com/TeamWiseFlow/xiaobei/blob/v5.5.2/awada/awada-server/src/routes/webhook-worktool.ts
- https://github.com/TeamWiseFlow/xiaobei/issues/440
- https://www.vulncheck.com/advisories/xiaobei-through-5.5.2-unauthenticated-webhook-message-injection
- https://github.com/TeamWiseFlow/xiaobei/issues/440
Znajdź błąd, zanim zrobi to atakujący.
Zaloguj się przez GitHub i uruchom pierwszy audyt w niecałą minutę. Plan darmowy nie wymaga karty kredytowej.