CVE-2026-61430
MervinPraison PraisonAI
PraisonAI before 1.6.78 contains a server-side request forgery vulnerability in the web_crawl tool that validates hostnames at check time but re-resolves them at connection time without IP pinning. Attackers can use DNS rebinding to bypass SSRF protection and retrieve internal HTTP response bodies from private or loopback services.
- CVSS
- 8.4
- EPSS
- - - percentile
- CISA KEV
- Not listed
- Published
- 2026.07.15