SSRF Vulnerability in PraisonAI Multi-Agent System
CVE-2026-57126

8.5HIGH

Key Information:

Status
Vendor
CVE Published:
14 September 2026

What is CVE-2026-57126?

The vulnerability in PraisonAI arises from the SpiderTools._validate_url function, which incorrectly handles hostname encodings without resolving DNS names before executing various fetching operations. This allows attackers to craft hostname requests that can resolve to loopback, private, link-local, or cloud-metadata addresses, thereby circumventing SSRF protections. Such exploitation may lead to unauthorized disclosure of internal responses and sensitive data. The issue has been addressed in version 1.6.58 of praisonaiagents.

Affected Version(s)

PraisonAI < 1.6.59

References

CVSS V3.1

Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.