CVE-2026-55537
HIGH
7,1
Source: [email protected]
Attack Vector: network
Attack Complexity: high
Privileges Required: low
User Interaction: none
Scope: changed
Confidentiality: high
Integrity: low
Availability: none
Description
AI Translation Available
PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.58, JobSubmitRequest.validate_webhook_url() accepts webhook_url when resolution raises socket.gaierror because the exception path uses except socket.gaierror: pass. JobExecutor._send_webhook() later performs a fresh lookup, allowing DNS changes to direct the request to an internal service. This issue is fixed in version 4.6.58.
367
Time-of-check Time-of-use (TOCTOU) Race Condition
IncompleteCommon Consequences
Security Scopes Affected:
Integrity
Other
Non-Repudiation
Potential Impacts:
Alter Execution Logic
Unexpected State
Modify Application Data
Modify Files Or Directories
Modify Memory
Other
Hide Activities
Applicable Platforms
All platforms may be affected
705
Incorrect Control Flow Scoping
IncompleteCommon Consequences
Security Scopes Affected:
Other
Potential Impacts:
Alter Execution Logic
Other
Applicable Platforms
All platforms may be affected
918
Server-Side Request Forgery (SSRF)
IncompleteCommon Consequences
Security Scopes Affected:
Confidentiality
Integrity
Access Control
Potential Impacts:
Read Application Data
Execute Unauthorized Code Or Commands
Bypass Protection Mechanism
Applicable Platforms
Technologies:
Web Based, AI/ML, Web Server
https://github.com/MervinPraison/PraisonAI/commit/2f9677abb2ea68eab864ee8b6a828…
https://github.com/MervinPraison/PraisonAI/releases/tag/v4.6.58
https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-rg5q-pp8p-f…