Webhook URL Validation Flaw in PraisonAI Affects Multi-Agent Teams System
CVE-2026-55535
6.8MEDIUM
What is CVE-2026-55535?
The Jobs API in PraisonAI, before version 4.6.58, contains a vulnerability where the validate_webhook_url() method fails to enforce proper binding of validated addresses. This oversight allows an attacker's webhook URL to potentially resolve to internal IP addresses, such as 127.0.0.1 or 169.254.169.254. As a result, this can lead to unauthorized access or manipulation of internal resources. Users are strongly advised to update to version 4.6.58 or later to mitigate this issue.
Affected Version(s)
PraisonAI < 4.6.58
