All vulnerabilities

GHSA-x92v-rpx6-p6cw

PyPI · praisonai

Summary

PraisonAI: Webhook signature verification skipped (fail-open) when secret unset, allowing forged inbound webhooks (WhatsApp & Linear bots)

References