GHSA-92x2-g374-gcvxHigh· 8.5▾ TwilightDuplicate Advisory: PraisonAI: DNS rebinding bypass in `web_crawl` SSRF protection allows internal response disclosure
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 46.8 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via GHSA
Last analysed / modified upstream
This advisory has been withdrawn because it is a duplicate of GHSA-qg25-6gc4-48mg. This link is maintained to preserve external references.
PraisonAI before 1.6.78 contains a server-side request forgery vulnerability in the web_crawl tool that validates hostnames at check time but re-resolves them at connection time without IP pinning. Attackers can use DNS rebinding to bypass SSRF protection and retrieve internal HTTP response bodies from private or loopback services.
praisonaiagents <= 1.6.77Refer to the advisory for the patched release.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-61430High· 8.5PraisonAI: DNS rebinding bypass in `web_crawl` SSRF protection allows internal response disclosure
GHSA-rc3q-9pxg-3jhrHigh· 8.5Duplicate Advisory: PraisonAI: Crawl4AI/Chromium backend is also affected by the `web_crawl` SSRF validation bypass
CVE-2026-55526High· 8.5praisonaiagents has an SSRF protection bypass in `spider_tools._host_is_blocked()` via DNS-resolved hostnames (`127.0.0.1.nip.io`)
CVE-2026-55524High· 7.5PraisonAI is a multi-agent teams system
CVE-2026-55525High· 7.5praisonaiagents web_crawl vulnerable to SSRF via redirect-following
CVE-2026-55523HighPraisonAI is a multi-agent teams system