CVE-2026-55523
published 2026-08-05CVE-2026-55523: PraisonAI is a multi-agent teams system. In versions 1.5.128 through 1.6.57, the praisonaiagents.tools.web_crawl_tools.web_crawl() function is vulnerable to…
PriorityP348high7.7CVSS 4.0
AVNACLATNPRNUINVCNVINVANSCHSINSANEXCRXIRXARXMAVXMACXMATXMPRXMUIXMVCXMVIXMVAXMSCXMSIXMSAXSXAUXRXVXREXUX
EPSS
0.36%
30.1th percentile
PraisonAI is a multi-agent teams system. In versions 1.5.128 through 1.6.57, the praisonaiagents.tools.web_crawl_tools.web_crawl() function is vulnerable to server-side request forgery. While it validates the initially supplied URL and blocks direct loopback and private destinations, its default httpx fallback uses httpx.Client(follow_redirects=True) and does not revalidate intermediate or final redirect targets. An attacker who can influence a URL passed to web_crawl(), directly or through an agent or tool workflow, can supply an attacker-controlled public URL that passes the initial host check and then redirects to loopback, private-network, or cloud metadata endpoints reachable from the host, with the redirected response body returned in the web_crawl() result. This constitutes an incomplete fix and patch bypass for the previously disclosed web_crawl SSRF class (GHSA-qq9r-63f6-v542 / CVE-2026-40160 and GHSA-8f4v-xfm9-3244), since the guard validates only the requested URL and not the destination actually fetched after redirection. This issue has been fixed in version 1.6.58.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mervinpraison | praisonaiagents | >= 1.5.128 < 1.6.58 | 1.6.58 |
CVSS provenance
nvdv4.07.7HIGHCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
ghsa6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
praisonaiagents has a `web_crawl` SSRF protection bypass via unchecked redirect targets
ghsa·2026-08-25·CVSS 6.5
CVE-2026-55523 [MEDIUM] CWE-918 praisonaiagents has a `web_crawl` SSRF protection bypass via unchecked redirect targets
praisonaiagents has a `web_crawl` SSRF protection bypass via unchecked redirect targets
## Summary
`praisonaiagents.tools.web_crawl_tools.web_crawl()` validates the initial URL and blocks direct loopback/private destinations by default, but the default httpx fallback still uses `httpx.Client(follow_redirects=True)` and does not revalidate redirect targets.
An attacker-controlled public URL can pass the initial host check, redirect to loopback/private/cloud metadata infrastructure, and have the redirected response body returned by `web_crawl()`.
This appears to be an incomplete fix / patch bypass for the published `web_crawl` SSRF class (`GHSA-qq9r-63f6-v542` / `CVE-2026-40160`, and `GHSA-8f4v-xfm9-3244`).
## Affected Component
Package:
```text
praisonaiagents
```
File:
```text
src
VulDB
MervinPraison PraisonAI 1.5.128-1.6.57 Web Crawl Tools web_crawl_tools.py praisonaiagents.tools.web_crawl_tools.web_crawl url server-side request forgery
vuldb·2026-08-05·CVSS 7.7
CVE-2026-55523 [HIGH] MervinPraison PraisonAI 1.5.128-1.6.57 Web Crawl Tools web_crawl_tools.py praisonaiagents.tools.web_crawl_tools.web_crawl url server-side request forgery
A vulnerability, which was classified as critical, has been found in MervinPraison PraisonAI 1.5.128-1.6.57. Affected by this issue is the function praisonaiagents.tools.web_crawl_tools.web_crawl of the file praisonaiagents/tools/web_crawl_tools.py of the component Web Crawl Tools. The manipulation of the argument url leads to server-side request forgery.
This vulnerability is uniquely identified as CVE-2026-55523. The attack is possible to be carried out remotely. No exploit exists.
It is advisable to upgrade the affected component.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-08-05
Published