Impact
PraisonAI before version 1.6.78 implements a web crawling tool that validates hostnames when the request is checked but re‑resolves those names when connecting to the target. This omission of IP pinning enables DNS rebinding attacks, allowing an attacker to bypass the server‑side request forgery (SSRF) protection and obtain the contents of internal or loopback HTTP services. The vulnerability can expose confidential data or internal state and enable further exploitation of those services. This weakness is categorized as CWE‑918.
Affected Systems
All installations of PraisonAI from the MervinPraison product line running a version earlier than 1.6.78 are affected.
Risk and Exploitability
The CVSS score of 8.4 classifies the issue as high severity. The EPSS score of less than 1% indicates a very low probability of exploitation at the time of analysis, and the vulnerability is not listed in the CISA KEV catalog. The likely attack requires an adversary who can reach the web_crawl endpoint and control the DNS resolution of target hostnames, making the vulnerability exploitable over the public network.
OpenCVE Enrichment