CVE-2026-61430: Mervinpraison Praisonai
High severity, CVSS 8.5. EPSS: 0.3% chance of exploitation in the next 30 days.
PraisonAI before 1.6.78 contains a server-side request forgery vulnerability in the web_crawl tool that validates hostnames at check time but re-resolves them at connection time without IP pinning. Attackers can use DNS rebinding to bypass SSRF protection and retrieve internal HTTP response bodies from private or loopback services.
Affected products
- Mervinpraison Praisonai: before 1.6.78 (fixed in 1.6.78)
Published 2026-07-15. Last modified 2026-07-15.