CVE-2026-55524
published 2026-08-05CVE-2026-55524: PraisonAI is a multi-agent teams system. In versions prior to 1.6.58, the web_crawl tool performs its SSRF check only on the initially supplied URL, allowing…
PriorityP347high7.5CVSS 3.1
AVNACHPRNUINSCCHILAN
EPSS
0.19%
9.3th percentile
PraisonAI is a multi-agent teams system. In versions prior to 1.6.58, the web_crawl tool performs its SSRF check only on the initially supplied URL, allowing the protection to be bypassed so the tool connects to attacker-chosen internal destinations. The check resolves the hostname once with socket.gethostbyname and rejects private/loopback/link-local results, but then passes the URL to a fetcher using httpx.Client(follow_redirects=True) (or urllib.request.urlopen when httpx is absent, which also follows redirects) that re-resolves the hostname at connect time with no further validation. This validate-here/fetch-there gap is exploitable through both HTTP redirects and DNS rebinding. If an attacker can influence URLs passed to web_crawl(), directly or through an agent/tool workflow, they can cause the PraisonAI host to fetch loopback, private-network, or cloud metadata endpoints reachable from that host, with the response body returned in the web_crawl() result. This issue has been fixed in version 1.6.58.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mervinpraison | praisonai | < 1.6.58 | 1.6.58 |
| mervinpraison | praisonaiagents | >= 0 < 1.6.58 | 1.6.58 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
praisonaiagents vulnerable to SSRF in web_crawl tool via redirect-following and DNS rebinding (validate-then-fetch gap)
ghsa·2026-08-25
CVE-2026-55524 [HIGH] CWE-367 praisonaiagents vulnerable to SSRF in web_crawl tool via redirect-following and DNS rebinding (validate-then-fetch gap)
praisonaiagents vulnerable to SSRF in web_crawl tool via redirect-following and DNS rebinding (validate-then-fetch gap)
The web_crawl tool performs its SSRF check only on the initial URL: it resolves the hostname once
with socket.gethostbyname and rejects private/loopback/link-local results. It then passes the URL to
a fetcher that uses httpx.Client(follow_redirects=True) - or urllib.request.urlopen when httpx is
absent, which also follows redirects - and re-resolves the hostname at connect time, with no further
validation. This validate-here/fetch-there gap is bypassable two independent ways: HTTP redirects and
DNS rebinding.
Affected code: src/praisonai-agents/praisonaiagents/tools/web_crawl_tools.py
- Single-shot validation (lines 229-238):
if os.environ.get("ALLOW_LOCAL_CRAWL") != "t
VulDB
MervinPraison PraisonAI up to 1.6.57 web_crawl server-side request forgery
vuldb·2026-08-05·CVSS 7.5
CVE-2026-55524 [HIGH] MervinPraison PraisonAI up to 1.6.57 web_crawl server-side request forgery
A vulnerability was found in MervinPraison PraisonAI up to 1.6.57. It has been classified as critical. This affects the function web_crawl. The manipulation leads to server-side request forgery.
This vulnerability is referenced as CVE-2026-55524. Remote exploitation of the attack is possible. No exploit is available.
Upgrading the affected component is recommended.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-08-05
Published