← Terug naar overzicht

xiaobei versions through 5.5.2 contain a critical vulnerability in the /webhook_worktool handler that lacks any authentication or signature validation. This allows unauthenticated attackers to inject arbitrary messages directly into the agent pipeline. The vulnerability is exploitable remotely without credentials, enabling malicious message publication through the webhook endpoint. Additionally, unvalidated media URL fetching in the same handler enables server-side request forgery (SSRF), allowing attackers to pivot and reach internal services. The flaw is located in the awada-server routing code for webhook handling. No patch appears to be available beyond version 5.5.2 at time of disclosure. The issue has been reported via GitHub issues and covered by VulnCheck advisories.

Affected products

  • xiaobei

Related CVE's

  • CVE-2026-85667

Categories

  • Enterprise Applications
  • Identity & Access
  • Web Technologies