Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
5049 articles · 189092 vulns · 37/41 feeds (7d)
← Back to list
7.2
CVE-2026-60091EXPLOITEDPATCHED
praisonai · praisonai

PraisonAI before 4.6.78 Unauthenticated SSRF via webhook_url

Description

PraisonAI before 4.6.78 contains an unauthenticated server-side request forgery vulnerability in the Jobs API /api/v1/runs endpoint. The webhook_url parameter is validated at request time but re-resolved at connection time, allowing attackers to use DNS rebinding to reach internal services with a blind SSRF attack.

Affected Products

VendorProductVersions
praisonaipraisonai0

References

  • https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-4w49-gwv8-fpjg(vendor-advisory)
  • https://www.vulncheck.com/advisories/praisonai-before-unauthenticated-ssrf-via-webhook-url(third-party-advisory)

Related News (1 articles)

Tier C
VulDB33d ago
CVE-2026-60091 | MervinPraison PraisonAI up to 4.6.77 Jobs API /api/v1/runs webhook_url server-side request forgery
→ No new info (linked only)
CVSS 3.17.2 NONE
CISA KEV❌ No
Actively exploited✅ Yes
Patch available
4.6.78
CWECWE-918
PublishedJul 10, 2026
Last enriched33d agov2
Trending Score1
Source articles1
Independent1
Info Completeness8/14
Missing: cvss, epss, kev, exploit, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

NONECVE-2026-61447EXP
PraisonAI before 1.6.78 Remote Code Execution via CodeAgent
Trending: 58
HIGHCVE-2026-47405
PraisonAI Platform missing role checks let any workspace member become owner and take over workspace membership
Trending: 4
HIGHCVE-2026-47406
praisonai-platform: Dependency endpoints accept any issue_id and dep_id without workspace ownership check, cross-workspace issue linking + read + delete IDOR
Trending: 4
NONECVE-2026-61445EXP
PraisonAI before 4.6.78 Arbitrary File Write and Command Execution
Trending: 1
CRITICALCVE-2026-61443EXP
PraisonAI before 1.6.78 Remote Code Execution via SkillTools
Trending: 1

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jul 10, 2026
Discovered by ZDM
Jul 10, 2026
Updated: description, severity, activelyExploited
Jul 10, 2026
Actively Exploited
Jul 10, 2026
Patch Available
Jul 10, 2026

Version History

v2
Last enriched 33d ago
v2Tier C33d ago

Updated severity to CRITICAL, marked as actively exploited, and corrected exploit availability to false.

descriptionseverityactivelyExploited
via VulDB
v133d ago

Initial creation