Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4205 articles · 197367 vulns · 37/41 feeds (7d)
← Back to list
7.5
CVE-2026-55525PATCHED
mervinpraison · praisonai

PraisonAI: SSRF via redirect-following in praisonaiagents web_crawl

Description

PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.58, the web_crawl function validates only the initial URL before _crawl_with_httpx uses httpx.Client(follow_redirects=True). Redirect targets are not revalidated, so an attacker who influences a crawl target can redirect a public URL to loopback, private network, or cloud metadata services while ALLOW_LOCAL_CRAWL remains disabled. The fetched internal response is returned to the agent context. This issue is fixed in version 1.6.58.

Affected Products

VendorProductVersions
mervinpraisonpraisonai< 4.6.58, < 1.6.58

References

  • https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-5r34-2g38-6569(x_refsource_CONFIRM)
  • https://github.com/MervinPraison/PraisonAI/commit/2f9677abb2ea68eab864ee8b6a828fd0141612e1(x_refsource_MISC)
  • https://github.com/MervinPraison/PraisonAI/releases/tag/v4.6.58(x_refsource_MISC)

Related News (1 articles)

Tier C
VulDB7h ago
CVE-2026-55525 | MervinPraison PraisonAI up to 1.6.57 Web Crawl web_crawl redirect
→ No new info (linked only)
CVSS 3.17.5 HIGH
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CISA KEV❌ No
Actively exploited❌ No
Patch available
praisonaiagents@1.6.58
CWECWE-918
PublishedAug 25, 2026
Trending Score44
Source articles1
Independent1
Info Completeness0/14
Missing: cve_id, title, description, vendor, product, versions, cvss, epss, cwe, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

HIGHCVE-2026-55533
PraisonAI: Authentication fail-open in Recipe server allows unauthenticated access when API key or JWT auth is configured without a secret
Trending: 44
HIGHCVE-2026-55538
PraisonAI: [Auth Bypass] `praisonai serve agents --api-key` is silently ignored — agent-invocation routes (`POST /agents`, `POST /agents/{agent_name}`) run unauthenticated
Trending: 44
HIGHCVE-2026-55539
PraisonAI: [Auth Bypass] PraisonAI async Jobs API (`/api/v1/runs`) has no authentication — unauthenticated job execution, result theft, cancel and delete
Trending: 36
NONECVE-2026-55541
PraisonAI: `--api-key` flag on `praisonai serve` is not properly enforced
Trending: 34
HIGHCVE-2026-55532
PraisonAI: Origin-validation bypass (startswith prefix match) enables unauthenticated cross-site request forgery against the PraisonAI MCP HTTP server
Trending: 34

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Aug 25, 2026
Discovered by ZDM
Aug 25, 2026
Patch Available
Aug 25, 2026