{"id":"GHSA-92x2-g374-gcvx","title":"Duplicate Advisory: PraisonAI: DNS rebinding bypass in `web_crawl` SSRF protection allows internal response disclosure","summary":"Duplicate Advisory: PraisonAI: DNS rebinding bypass in `web_crawl` SSRF protection allows internal response disclosure","severity":"high","cvss":8.5,"cwe":["CWE-918"],"vendor":"praisonaiagents","product":"praisonaiagents","ecosystem":"pip","affected":["praisonaiagents <= 1.6.77"],"published":"2026-07-15","updated":"2026-10-08","sourceUpdated":"2026-10-08T16:36:45Z","source":"GHSA","sourceUrl":"https://github.com/advisories/GHSA-92x2-g374-gcvx","references":[{"url":"https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-qg25-6gc4-48mg"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-61430"},{"url":"https://www.vulncheck.com/advisories/praisonai-before-dns-rebinding-ssrf-via-web-crawl"},{"url":"https://github.com/advisories/GHSA-92x2-g374-gcvx"}],"tags":["ghsa","pip"],"ingestedAt":"2026-10-08T16:52:14.781Z","slug":"GHSA-92x2-g374-gcvx","body":"## Overview\n\n### Duplicate Advisory\nThis advisory has been withdrawn because it is a duplicate of GHSA-qg25-6gc4-48mg. This link is maintained to preserve external references.\n\n### Original Description\nPraisonAI before 1.6.78 contains a server-side request forgery vulnerability in the web_crawl tool that validates hostnames at check time but re-resolves them at connection time without IP pinning. Attackers can use DNS rebinding to bypass SSRF protection and retrieve internal HTTP response bodies from private or loopback services.\n\n## Affected packages\n\n- `praisonaiagents <= 1.6.77`\n\n## Remediation\n\nRefer to the advisory for the patched release.","depth":"twilight","depthScore":47,"depthScoreParts":{"impact":46.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}