Impact
PraisonAI versions prior to 1.6.78 contain a server‑side request forgery flaw in the Crawl4AI/Chromium backend. This flaw is classified as CWE‑918. The flaw allows an attacker to bypass SSRF validation by manipulating DNS records and HTTP redirects. When exploited, the backend can issue requests to internal services and return their responses, exposing sensitive data such as canary values. The flaw carries a CVSS score of 8.4, indicating high severity and a high potential impact on confidentiality and integrity.
Affected Systems
The product MervinPraison:PraisonAI is vulnerable. Versions before 1.6.78 are affected and may expose internal network resources if the Crawl4AI/Chromium backend is allowed to reach them.
Risk and Exploitability
An attacker who can submit a URL to the Crawl4AI component can craft a malicious address that initially resolves to a benign external host, passes the SSRF check, and then uses DNS rebinding or an HTTP redirect to reach an internal server. The headless Chromium engine follows the redirect and returns the internal response to the attacker. Because the exploit requires only crafted URLs and can be performed over the public interface, the likelihood of exploitation is significant, especially in environments with unrestricted network access from the backend. The EPSS score of <1% indicates that while exploitation is possible, widespread use is unlikely, despite the high CVSS of 8.4. It is not currently listed in CISA’s KEV catalog.
OpenCVE Enrichment