Impact
PraisonAI, a multi‑agent team tool, validates URLs via SpiderTools._validate_url before performing operations such as scrape_page, crawl, extract_links, extract_text, or fetching URL mentions. The validation checks literal host encodings but does not resolve DNS names. Consequently, an attacker can supply a hostname that resolves to a loopback, private, link‑local, or cloud‑metadata address, bypassing the SSRF guard without a rebinding race. The agent will then request internal resources, making internal responses available to the attacker. The flaw, identified as CWE‑918, grants the attacker a purely remote access path to internal services and data with no timing side‑channels. The issue is fixed in praisonaiagents 1.6.58.
Affected Systems
Products from MervinPraison under the PraisonAI suite, specifically the praisonaiagents component. Versions prior to 1.6.58 are vulnerable; the fix was released with praisonai GitHub release v4.6.58). Any deployment using an earlier commit or tag that incorporates praisonaiagents 1.6.57 or lower is at risk.
Risk and Exploitability
The CVSS score of 8.5 indicates high severity, while the EPSS score is <1%, giving very low but nonzero exploitation probability data. The flaw is not listed in CISA's KEV catalog, so no known large‑scale exploitation is reported yet. Because the attack path relies on the agent's ability to process external URLs, the vulnerability can be exploited remotely by probing the AI interface with specially crafted inputs. Bypassing the SSRF policy without a rebinding race lowers the infrastructure cost for attackers.
OpenCVE Enrichment
Github GHSA