Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-vxgj-xg5c-p4h7 | praisonaiagents: SSRF guard validates literal IPs only and never resolves DNS |
Mon, 14 Sep 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.58, SpiderTools._validate_url calls _host_is_blocked, which checks literal host encodings but does not resolve DNS names before scrape_page, crawl, extract_links, extract_text, or URL-mention fetches connect. An attacker-controlled hostname resolving to a loopback, private, link-local, or cloud-metadata address therefore bypasses the SSRF policy without a rebinding race and can expose internal responses to the agent. This issue is fixed in praisonaiagents 1.6.58. | |
| Title | praisonaiagents: SSRF guard validates literal IPs only and never resolves DNS | |
| Weaknesses | CWE-918 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-09-14T19:15:17.276Z
Reserved: 2026-06-24T00:33:17.707Z
Link: CVE-2026-57126
Updated: 2026-09-14T19:14:56.249Z
Status : Received
Published: 2026-09-14T15:17:06.040
Modified: 2026-09-14T20:16:48.440
Link: CVE-2026-57126
No data.
OpenCVE Enrichment
No data.
Github GHSA