Skip to content

No Webhook Signature Verification (Critical Security Vulnerability) #6

@AnisGLZ

Description

@AnisGLZ

Like Repo 032, this bot does not verify the X-Hub-Signature header on incoming POST requests. The entire message handling pipeline can be triggered by any HTTP client that posts valid-looking JSON to the webhook endpoint. Combined with the fact that the bot may take real actions (sending messages, triggering integrations), this is a critical unauthenticated remote-trigger vulnerability.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions