CRITICAL 9.3 NVD

CVE-2026-85667

xiaobei through 5.5.2 fails to implement authentication or signature validation on webhook endpoints, allowing unauthenticated attackers to inject arbitrary mes

xiaobei through 5.5.2 fails to implement authentication or signature validation on webhook endpoints, allowing unauthenticated attackers to inject arbitrary messages into the agent pipeline. Attackers can publish malicious messages via the /webhook_worktool handler and exploit unvalidated media URL fetching to perform server-side request forgery against internal services.

References

Published: 2026-09-04 · Source: NVD · Feed updated: 2026-09-04
This critical severity vulnerability with a CVSS score of 9.3 was published on 2026-09-04 via NVD.

Risk Timeline

CVE Disclosed2026-09-04 · -1 days ago

Remediation Resources

vulnfeed aggregates 8217 vulnerabilities from NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.