PT-2026-57190 · Praisonai · Praisonai
CVSS v3.1
7.2
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
PraisonAI versions prior to 4.6.78
Description
An unauthenticated server-side request forgery (SSRF) exists in the Jobs API endpoint '/api/v1/runs'. The issue occurs because the
webhook url parameter is validated during the initial request but re-resolved during the connection phase. This allows attackers to employ DNS rebinding—a technique used to bypass security filters by changing the IP address associated with a domain name between the time of validation and the time of use—to conduct blind SSRF attacks against internal services.Recommendations
Update PraisonAI to version 4.6.78 or later.
As a temporary mitigation, restrict access to the '/api/v1/runs' endpoint or avoid using the
webhook url parameter until the update is applied.Exploit
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Praisonai