Webhook URL Validation Flaw in PraisonAI Affects Multi-Agent Teams System
CVE-2026-55535

6.8MEDIUM

Key Information:

Status
Vendor
CVE Published:
25 August 2026

What is CVE-2026-55535?

The Jobs API in PraisonAI, before version 4.6.58, contains a vulnerability where the validate_webhook_url() method fails to enforce proper binding of validated addresses. This oversight allows an attacker's webhook URL to potentially resolve to internal IP addresses, such as 127.0.0.1 or 169.254.169.254. As a result, this can lead to unauthorized access or manipulation of internal resources. Users are strongly advised to update to version 4.6.58 or later to mitigate this issue.

Affected Version(s)

PraisonAI < 4.6.58

References

CVSS V3.1

Score:
6.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.