PT-2026-57190 · Praisonai · Praisonai

·

CVE-2026-60091

·

Published

2026-07-10

·

Updated

2026-07-10

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions PraisonAI versions prior to 4.6.78
Description An unauthenticated server-side request forgery (SSRF) exists in the Jobs API endpoint '/api/v1/runs'. The issue occurs because the webhook url parameter is validated during the initial request but re-resolved during the connection phase. This allows attackers to employ DNS rebinding—a technique used to bypass security filters by changing the IP address associated with a domain name between the time of validation and the time of use—to conduct blind SSRF attacks against internal services.
Recommendations Update PraisonAI to version 4.6.78 or later. As a temporary mitigation, restrict access to the '/api/v1/runs' endpoint or avoid using the webhook url parameter until the update is applied.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-60091
GHSA-4W49-GWV8-FPJG

Affected Products

Praisonai