CRITICAL 9.3 NVD
CVE-2026-85667
xiaobei through 5.5.2 fails to implement authentication or signature validation on webhook endpoints, allowing unauthenticated attackers to inject arbitrary mes
xiaobei through 5.5.2 fails to implement authentication or signature validation on webhook endpoints, allowing unauthenticated attackers to inject arbitrary messages into the agent pipeline. Attackers can publish malicious messages via the /webhook_worktool handler and exploit unvalidated media URL fetching to perform server-side request forgery against internal services.
References
- https://github.com/TeamWiseFlow/xiaobei
- https://github.com/TeamWiseFlow/xiaobei/blob/v5.5.2/awada/awada-server/src/routes/webhook-
- https://github.com/TeamWiseFlow/xiaobei/issues/440
- https://www.vulncheck.com/advisories/xiaobei-through-5.5.2-unauthenticated-webhook-message
This critical severity vulnerability with a CVSS score of 9.3 was published on 2026-09-04 via NVD.
Risk Timeline
CVE Disclosed2026-09-04 · -1 days ago
Remediation Resources
vulnfeed aggregates 8217 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.