Web Application Vulnerability in PraisonAI by Mervin Praison
CVE-2026-57115
6.5MEDIUM
What is CVE-2026-57115?
PraisonAI, a multi-agent team system, has a vulnerability related to improper URL validation in its SpiderTools.scrape_page function. In versions prior to 1.6.59, the system allows requests.Session.get to automatically follow redirects after validating only the initial URL. This can lead to potentially sensitive information being disclosed when a public URL redirects to a loopback or private address, without the necessary revalidation. The issue has been addressed in version 1.6.59, enhancing the security of link extraction and crawling functionalities.
Affected Version(s)
PraisonAI < 4.6.59
praisonaiagents < 1.6.59
