CVE-2026-55523
Description
PraisonAI is a multi-agent teams system. In versions 1.5.128 through 1.6.57, the praisonaiagents.tools.web_crawl_tools.web_crawl() function is vulnerable to server-side request forgery. While it validates the initially supplied URL and blocks direct loopback and private destinations, its default httpx fallback uses httpx.Client(follow_redirects=True) and does not revalidate intermediate or final redirect targets. An attacker who can influence a URL passed to web_crawl(), directly or through an agent or tool workflow, can supply an attacker-controlled public URL that passes the initial host check and then redirects to loopback, private-network, or cloud metadata endpoints reachable from the host, with the redirected response body returned in the web_crawl() result. This constitutes an incomplete fix and patch bypass for the previously disclosed web_crawl SSRF class (GHSA-qq9r-63f6-v542 / CVE-2026-40160 and GHSA-8f4v-xfm9-3244), since the guard validates only the requested URL and not the destination actually fetched after redirection. This issue has been fixed in version 1.6.58.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
praisonaiagentsPyPI | >= 1.5.128, < 1.6.58 | 1.6.58 |
Affected products
2Patches
Vulnerability mechanics
References
5- github.com/advisories/GHSA-8hjw-25cg-g52hghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2026-55523ghsaADVISORY
- github.com/MervinPraison/PraisonAI/commit/2f9677abb2ea68eab864ee8b6a828fd0141612e1ghsaWEB
- github.com/MervinPraison/PraisonAI/releases/tag/v4.6.58ghsaWEB
- github.com/MervinPraison/PraisonAI/security/advisories/GHSA-8hjw-25cg-g52hnvdWEB
News mentions
1- PraisonAI: Three High-Severity SSRF and Code Execution Flaws Disclosed TogetherVypr Intelligence · Aug 5, 2026