PT-2026-61797 · Unknown+1 · Praisonaiagents+1
CVE-2026-57143
·
Published
2026-06-18
·
Updated
2026-07-23
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
praisonaiagents (affected versions not specified)
Description
A Server-Side Request Forgery (SSRF) issue exists in the SearxNG and
search web search tools. The searxng url variable is passed to the requests.get() function without validation of the scheme, host, or port. Since this variable is exposed as a tool parameter to the Large Language Model (LLM) and these tools are part of the default agent toolset, the issue can be triggered via prompt injection when an agent processes untrusted content such as web pages or files.This allows an attacker to force the server to make requests to arbitrary internal endpoints, enabling the reading of internal services and APIs that return JSON, and internal host and port enumeration. In cloud environments, the instance metadata endpoint (169.254.169.254) is reachable, which may lead to the exposure of IAM credentials. The vulnerability is present in the
searxng search() and search searxng() functions.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
As a temporary workaround, restrict the use of the
searxng url parameter in the search web() and searxng search() functions to prevent arbitrary internal requests.RCE
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Searxng
Praisonaiagents