CRITICAL
9.1 CVE-2026-85667 Published 4 Sept 2026
Xiaobei Webhook Endpoint Authentication Bypass
Worried this affects one of your servers?
Xiaobei versions up to 5.5.2 are affected by a lack of authentication and signature validation on webhook endpoints.
Xiaobei allows unauthenticated attackers to inject arbitrary messages into the agent pipeline via the /webhook_worktool handler.
Exploiting unvalidated media URL fetching, attackers can perform server-side request forgery against internal services.
Reference: CVE-2026-85667 on NVD
← Back to Security News