PT-2026-31789 · Unknown · Praisonaiagents
Published
2026-04-09
·
Updated
2026-04-10
·
CVE-2026-40150
CVSS v3.1
7.7
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
PraisonAIAgents versions prior to 1.5.128
Description
PraisonAIAgents is a multi-agent teams system. The
web crawl() function in praisonaiagents/tools/web crawl tools.py accepts arbitrary URLs from AI agents without validation. This includes a lack of scheme allowlisting, hostname/IP blocklisting, or private network checks before fetching. This allows an attacker, or through prompt injection in crawled content, to force the agent to fetch cloud metadata endpoints, internal services, or local files via file:// URLs.Recommendations
Update PraisonAIAgents to version 1.5.128 or later.
Exploit
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Praisonaiagents