CVE-2026-55535

medium

Description

PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.58, the Jobs API validate_webhook_url() path fails open on socket.gaierror and does not bind the validated address to the later request. An attacker webhook_url can later resolve to 127.0.0.1, 169.254.169.254, or another internal address. This issue is fixed in version 4.6.58.

References

https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-hmfx-4v44-9qw9

https://github.com/MervinPraison/PraisonAI/releases/tag/v4.6.58

https://github.com/MervinPraison/PraisonAI/commit/2f9677abb2ea68eab864ee8b6a828fd0141612e1

Details

Source: Mitre, NVD

Published: 2026-08-25

Updated: 2026-08-25

Risk Information

CVSS v2

Base Score: 5.4

Vector: CVSS2#AV:N/AC:H/Au:N/C:C/I:N/A:N

Severity: Medium

CVSS v3

Base Score: 6.8

Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N

Severity: Medium

EPSS

EPSS: 0.00219