PT-2026-81326 · Praisonai · Praisonai

·

CVE-2026-55535

·

Published

2026-08-25

·

Updated

2026-09-10

CVSS v3.1

6.8

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions PraisonAI versions prior to 4.6.58
Description The Jobs API contains a flaw where the validate webhook url() function fails open when a socket.gaierror occurs during DNS resolution. This allows the webhook url parameter to bypass validation if the domain is unresolvable or via a DNS rebinding attack, where a domain initially resolves to a public IP to pass validation and subsequently resolves to an internal address. This can lead to Server-Side Request Forgery (SSRF), enabling an unauthenticated attacker to make requests to internal HTTP services, such as admin panels, databases, or cloud metadata APIs like http://169.254.169.254/.
Recommendations Update PraisonAI to version 4.6.58. As a temporary mitigation, restrict or avoid using the webhook url parameter in the Jobs API until the update is applied.

Exploit

Fix

SSRF

Time Of Check To Time Of Use

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-55535
GHSA-HMFX-4V44-9QW9
PYSEC-2026-3890

Affected Products

Praisonai