SCA: security update for praisonaiagents (GHSA-6g59-gm2v-qhvq)

high Tenable Self-Hosted Container Security Plugin ID 473822

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- PraisonAI versions before 1.6.78 contain a server-side request forgery vulnerability in the
Crawl4AI/Chromium backend that allows attackers to bypass SSRF validation by exploiting DNS rebinding and
HTTP redirects. Attackers can craft URLs that resolve to internal services after the initial validation
check, enabling the headless browser to follow redirects and read internal responses including sensitive
canary values. (CVE-2026-61429)

Solution

Update the praisonaiagents library and its related packages to version 1.6.78 or later.

See Also

https://github.com/advisories/GHSA-6g59-gm2v-qhvq

Plugin Details

Severity: High

ID: 473822

Version: Revision 1.1

Type: Local

Family: SCA Checks

Published: 10/8/2026

Updated: 10/8/2026

Risk Information

VPR

Risk Factor: Low

Score: 3.9

Percentile: 52.84

Vendor

Vendor Severity: High

CVSS v2

Risk Factor: High

Base Score: 7.5

Temporal Score: 5.5

Vector: CVSS2#AV:N/AC:L/Au:S/C:C/I:P/A:N

CVSS Score Source: CVE-2026-61429

CVSS v3

Risk Factor: High

Base Score: 8.5

Temporal Score: 7.4

Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

CVSS v4

Risk Factor: High

Base Score: 8.4

Threat Score: 5.7

Threat Vector: CVSS:4.0/E:U

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:N/SC:H/SI:L/SA:N

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 10/7/2026

Vulnerability Publication Date: 7/11/2026

Reference Information

CVE: CVE-2026-61429