SSRF Vulnerability in PraisonAI Affected by Internal Destination Exploits
CVE-2026-55524

7.5HIGH

Key Information:

Status
Vendor
CVE Published:
5 August 2026

What is CVE-2026-55524?

The PraisonAI multi-agent teams system is impacted by a Server-Side Request Forgery vulnerability in its web_crawl tool. In versions prior to 1.6.58, the tool's SSRF protection is inadequate as it only validates the initial supplied URL. This gap allows attackers to manipulate redirection and DNS to access sensitive internal resources, including loopback and private networks. Exploitation requires influencing the URLs provided to web_crawl() through various means, potentially exposing confidential data. The issue has been resolved in version 1.6.58, reinforcing the system's integrity against such attacks.

Affected Version(s)

PraisonAI < 1.6.58

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.