Multi-Agent Systems Vulnerability in PraisonAI by MervinPraison
CVE-2026-55537

7.1HIGH

Key Information:

Status
Vendor
CVE Published:
25 August 2026

What is CVE-2026-55537?

PraisonAI, a multi-agent teams system, has a vulnerability in the JobSubmitRequest component that improperly handles DNS resolution errors. Specifically, before version 4.6.58, the method validate_webhook_url() fails to adequately address exceptions raised during webhook URL validation. This oversight can be exploited, allowing external DNS changes to redirect webhook requests to unauthorized internal services. The issue has been addressed in version 4.6.58, enhancing the security of request handling and preventing potential data exposure.

Affected Version(s)

PraisonAI < 4.6.58

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.