High severity7.5NVD Advisory· Published Aug 25, 2026· Updated Aug 25, 2026
CVE-2026-55525
CVE-2026-55525
Description
PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.58, the web_crawl function validates only the initial URL before _crawl_with_httpx uses httpx.Client(follow_redirects=True). Redirect targets are not revalidated, so an attacker who influences a crawl target can redirect a public URL to loopback, private network, or cloud metadata services while ALLOW_LOCAL_CRAWL remains disabled. The fetched internal response is returned to the agent context. This issue is fixed in version 1.6.58.
Affected products
2Patches
Vulnerability mechanics
References
4News mentions
0No linked articles in our index yet.