xiaobei webhook endpoint lacks authentication, allows SSRF attacks
xiaobei through version 5.5.2 fails to validate webhook authentication, allowing unauthenticated attackers to inject malicious messages into the agent pipeline and exploit unvalidated media URL fetching to perform server-side request forgery attacks.
Disclosed 4 September 2026 · Record updated 13 September 2026
Impact
Unauthenticated attackers can inject arbitrary messages into the agent pipeline and perform SSRF attacks against internal services via the /webhook_worktool handler
Our coverage
No articles linked to this incident yet.
Sources
- github.comhttps://github.com/advisories/GHSA-g573-j843-xr77
