Impact
PraisonAI’s SpiderTools component performs an HTTP GET on a user supplied URL and automatically follows any redirects. Before version praisonaiagents 1.6.59, only the original URL was validated; the redirect target was not re‑checked. As a result, an attacker can supply a URL that points to an internal service—such as a loopback, link‑local, or metadata endpoint—and cause the tool to retrieve and expose the response body. This allows sensitive data to be read from otherwise protected services. The weakness is a classic Server‑Side Request Forgery (CWE‑918).
Affected Systems
The vulnerability exists in MervinPraison:PraisonAI and praisonaiagents. All releases of praisonaiagents older than 1.6.59 are affected; any PraisonAI deployment using those versions should be considered vulnerable. No specific larger‑than‑1.6.59 versions are listed as impacted.
Risk and Exploitability
The CVSS score of 6.5 classifies this as medium impact. The EPSS score of 0.00257 indicates a very low exploitation probability, suggesting limited likelihood of real-world attacks. The vulnerability is not listed in CISA KEV, indicating no public operational exploitation at this time. Yet, if an application publicly exposes SpiderTools.scrape_page to unauthenticated users, the attacker can exploit SSRF by supplying a malicious URL, leading the system to fetch and return data from internal or private endpoints. This requires network connectivity from the PraisonAI host to the target address and no advanced credentials.
OpenCVE Enrichment
Github GHSA