Sunday, 13 September 2026
8 agent hacks today 7 vs yesterday (1)

xiaobei webhook endpoint lacks authentication, allows SSRF attacks

xiaobei through version 5.5.2 fails to validate webhook authentication, allowing unauthenticated attackers to inject malicious messages into the agent pipeline and exploit unvalidated media URL fetching to perform server-side request forgery attacks.

Disclosed 4 September 2026 · Record updated 13 September 2026

Impact

Unauthenticated attackers can inject arbitrary messages into the agent pipeline and perform SSRF attacks against internal services via the /webhook_worktool handler

Our coverage

No articles linked to this incident yet.

Sources

  1. github.comhttps://github.com/advisories/GHSA-g573-j843-xr77