VYPR
Unrated severityNVD Advisory· Published Jul 15, 2026· Updated Jul 15, 2026

PraisonAI before 1.6.78 DNS Rebinding SSRF via web_crawl

CVE-2026-61430

Description

PraisonAI before 1.6.78 contains a server-side request forgery vulnerability in the web_crawl tool that validates hostnames at check time but re-resolves them at connection time without IP pinning. Attackers can use DNS rebinding to bypass SSRF protection and retrieve internal HTTP response bodies from private or loopback services.

Affected products

2

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.