{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/xiaobei--5.5.2/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:xiaobei:xiaobei:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":9.1,"id":"CVE-2026-85667"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["xiaobei (\u003c= 5.5.2)"],"_cs_severities":["critical"],"_cs_tags":["webserver","vulnerability","cve"],"_cs_type":"advisory","_cs_vendors":["xiaobei"],"content_html":"\u003cp\u003eThe xiaobei application, up to and including version 5.5.2, contains a critical vulnerability where webhook endpoints fail to implement necessary authentication or signature validation. This flaw allows unauthenticated remote attackers to interact directly with the application's internal messaging pipeline via the /webhook_worktool handler. By submitting crafted payloads, an attacker can inject arbitrary messages, leading to potential remote code execution (RCE) within the agent pipeline. Furthermore, the application processes media URLs provided via these webhooks without adequate validation. This behavior can be exploited by attackers to conduct server-side request forgery (SSRF) attacks, allowing them to probe or interact with services located within the internal network that are otherwise inaccessible from the public internet. Given the lack of defensive controls on these endpoints, organizations using xiaobei versions 5.5.2 and earlier are at high risk of unauthorized system access and internal service compromise.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-85667 allows an unauthenticated attacker to execute code within the agent pipeline and leverage the server to reach internal network resources. This poses a significant threat of data exfiltration, lateral movement, and total system compromise.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImmediately restrict network access to the /webhook_worktool endpoint to known, trusted IP addresses using a reverse proxy or Web Application Firewall (WAF).\u003c/li\u003e\n\u003cli\u003eAudit all incoming webhook traffic for anomalous payloads targeting internal internal service URLs.\u003c/li\u003e\n\u003cli\u003eUpgrade xiaobei to a version released after 5.5.2 that implements cryptographic signature validation for webhook requests (CVE-2026-85667).\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-04T15:26:15Z","date_published":"2026-09-04T15:26:15Z","id":"https://feed.craftedsignal.io/briefs/2026-09-xiaobei-unauth-webhook/","summary":"The xiaobei product through version 5.5.2 lacks authentication on webhook endpoints, enabling unauthenticated remote code execution via pipeline message injection and server-side request forgery (SSRF) via malicious media URL fetching.","title":"Unauthenticated RCE and SSRF in xiaobei via Webhook Injection","url":"https://feed.craftedsignal.io/briefs/2026-09-xiaobei-unauth-webhook/"}],"language":"en","title":"CraftedSignal Threat Feed - Xiaobei (\u003c= 5.5.2)","version":"https://jsonfeed.org/version/1.1"}