Description
PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.58, SpiderTools._validate_url calls _host_is_blocked, which checks literal host encodings but does not resolve DNS names before scrape_page, crawl, extract_links, extract_text, or URL-mention fetches connect. An attacker-controlled hostname resolving to a loopback, private, link-local, or cloud-metadata address therefore bypasses the SSRF policy without a rebinding race and can expose internal responses to the agent. This issue is fixed in praisonaiagents 1.6.58.
Published: 2026-09-14
Score: 8.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Server‑Side Request Forgery (SSRF) leading to internal network exposure
Action: Immediate Patch
AI Analysis

Impact

PraisonAI, a multi‑agent team tool, validates URLs via SpiderTools._validate_url before performing operations such as scrape_page, crawl, extract_links, extract_text, or fetching URL mentions. The validation checks literal host encodings but does not resolve DNS names. Consequently, an attacker can supply a hostname that resolves to a loopback, private, link‑local, or cloud‑metadata address, bypassing the SSRF guard without a rebinding race. The agent will then request internal resources, making internal responses available to the attacker. The flaw, identified as CWE‑918, grants the attacker a purely remote access path to internal services and data with no timing side‑channels. The issue is fixed in praisonaiagents 1.6.58.

Affected Systems

Products from MervinPraison under the PraisonAI suite, specifically the praisonaiagents component. Versions prior to 1.6.58 are vulnerable; the fix was released with praisonai GitHub release v4.6.58). Any deployment using an earlier commit or tag that incorporates praisonaiagents 1.6.57 or lower is at risk.

Risk and Exploitability

The CVSS score of 8.5 indicates high severity, while the EPSS score is <1%, giving very low but nonzero exploitation probability data. The flaw is not listed in CISA's KEV catalog, so no known large‑scale exploitation is reported yet. Because the attack path relies on the agent's ability to process external URLs, the vulnerability can be exploited remotely by probing the AI interface with specially crafted inputs. Bypassing the SSRF policy without a rebinding race lowers the infrastructure cost for attackers.

Generated by OpenCVE AI on September 21, 2026 at 00:11 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade agent to version 1.6.58 or later, which resolves DNS before enforcing the SSRF guard.
  • Configure the agent with a strict outbound proxy or firewall that blocks internal IP ranges, limiting accidental internal requests.
  • If an upgrade is the agent’s external URL fetching features until a patch is applied.

Generated by OpenCVE AI on September 21, 2026 at 00:11 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-vxgj-xg5c-p4h7 praisonaiagents: SSRF guard validates literal IPs only and never resolves DNS
History

Tue, 15 Sep 2026 05:45:00 +0000

Type Values Removed Values Added
First Time appeared Mervinpraison
Mervinpraison praisonai
Vendors & Products Mervinpraison
Mervinpraison praisonai

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.58, SpiderTools._validate_url calls _host_is_blocked, which checks literal host encodings but does not resolve DNS names before scrape_page, crawl, extract_links, extract_text, or URL-mention fetches connect. An attacker-controlled hostname resolving to a loopback, private, link-local, or cloud-metadata address therefore bypasses the SSRF policy without a rebinding race and can expose internal responses to the agent. This issue is fixed in praisonaiagents 1.6.58.
Title praisonaiagents: SSRF guard validates literal IPs only and never resolves DNS
Weaknesses CWE-918
References
Metrics cvssV3_1

{'score': 8.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Subscriptions

Mervinpraison Praisonai
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-14T19:15:17.276Z

Reserved: 2026-06-24T00:33:17.707Z

Link: CVE-2026-57126

cve-icon Vulnrichment

Updated: 2026-09-14T19:14:56.249Z

cve-icon NVD

Status : Deferred

Published: 2026-09-14T15:17:06.040

Modified: 2026-09-15T14:45:28.563

Link: CVE-2026-57126

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T00:15:06Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)