CVE-2026-61429
published 2026-07-11CVE-2026-61429: PraisonAI versions before 1.6.78 contain a server-side request forgery vulnerability in the Crawl4AI/Chromium backend that allows attackers to bypass SSRF…
PriorityP352high8.5CVSS 3.1
AVNACLPRLUINSCCHILAN
EPSS
0.35%
28.5th percentile
PraisonAI versions before 1.6.78 contain a server-side request forgery vulnerability in the Crawl4AI/Chromium backend that allows attackers to bypass SSRF validation by exploiting DNS rebinding and HTTP redirects. Attackers can craft URLs that resolve to internal services after the initial validation check, enabling the headless browser to follow redirects and read internal responses including sensitive canary values.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mervinpraison | praisonai | < 1.6.78 | 1.6.78 |
CVSS provenance
nvdv3.18.5HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N
nvdv4.08.4HIGHCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:N/SC:H/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
MervinPraison PraisonAI up to 1.6.77 Crawl4AI server-side request forgery (EUVD-2026-43178)
vuldb·2026-07-11·CVSS 8.5
CVE-2026-61429 [HIGH] MervinPraison PraisonAI up to 1.6.77 Crawl4AI server-side request forgery (EUVD-2026-43178)
A vulnerability classified as problematic was found in MervinPraison PraisonAI up to 1.6.77. Affected by this issue is some unknown functionality of the component Crawl4AI. Executing a manipulation can lead to server-side request forgery.
This vulnerability appears as CVE-2026-61429. The attack may be performed from remote. There is no available exploit.
GHSA
PraisonAI versions before 1.6.78 contain a server-side request forgery vulnerability in the Crawl4AI/Chromium backend that allows attackers to bypass SSRF validation by exploiting DNS rebinding and HT
ghsa_unreviewed·2026-07-11
CVE-2026-61429 [HIGH] CWE-918 PraisonAI versions before 1.6.78 contain a server-side request forgery vulnerability in the Crawl4AI/Chromium backend that allows attackers to bypass SSRF validation by exploiting DNS rebinding and HT
PraisonAI versions before 1.6.78 contain a server-side request forgery vulnerability in the Crawl4AI/Chromium backend that allows attackers to bypass SSRF validation by exploiting DNS rebinding and HTTP redirects. Attackers can craft URLs that resolve to internal services after the initial validation check, enabling the headless browser to follow redirects and read internal responses including sensitive canary values.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-07-11
Published