Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-hmfx-4v44-9qw9 | PraisonAI vulnerable to Server-Side Request Forgery via DNS rebinding bypass in webhook_url validation |
Tue, 25 Aug 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 25 Aug 2026 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mervinpraison
Mervinpraison praisonai |
|
| Vendors & Products |
Mervinpraison
Mervinpraison praisonai |
Tue, 25 Aug 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.58, the Jobs API validate_webhook_url() path fails open on socket.gaierror and does not bind the validated address to the later request. An attacker webhook_url can later resolve to 127.0.0.1, 169.254.169.254, or another internal address. This issue is fixed in version 4.6.58. | |
| Title | PraisonAI: Server-Side Request Forgery via DNS rebinding bypass in webhook_url validation | |
| Weaknesses | CWE-367 CWE-918 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-08-25T18:16:28.163Z
Reserved: 2026-06-16T23:01:04.074Z
Link: CVE-2026-55535
Updated: 2026-08-25T18:16:03.283Z
Status : Received
Published: 2026-08-25T15:16:34.307
Modified: 2026-08-25T19:16:49.577
Link: CVE-2026-55535
No data.
OpenCVE Enrichment
Updated: 2026-08-25T16:45:04Z
Github GHSA