SSRF Vulnerability in PraisonAI Multi-Agent System
CVE-2026-57126
8.5HIGH
What is CVE-2026-57126?
The vulnerability in PraisonAI arises from the SpiderTools._validate_url function, which incorrectly handles hostname encodings without resolving DNS names before executing various fetching operations. This allows attackers to craft hostname requests that can resolve to loopback, private, link-local, or cloud-metadata addresses, thereby circumventing SSRF protections. Such exploitation may lead to unauthorized disclosure of internal responses and sensitive data. The issue has been addressed in version 1.6.58 of praisonaiagents.
Affected Version(s)
PraisonAI < 1.6.59
