{"data":{"id":"3a82cd91-f5ba-4786-bd65-0d56c3da9087","title":"GHSA-4w49-gwv8-fpjg: PraisonAI: Jobs API is unauthenticated by default and allows attacker-controlled webhook SSRF","summary":"PraisonAI's Async Jobs API enables API-key middleware only when PRAISONAI_JOBS_API_KEY is set, so all endpoints are unauthenticated by default. An unauthenticated POST /api/v1/runs accepts an attacker-controlled webhook_url, and the server POSTs job payloads to it via httpx, with a DNS-rebinding bypass of the request-time SSRF check that reaches internal services as a blind SSRF.","solution":"N/A -- no mitigation discussed in source.","labels":["security"],"sourceUrl":"https://github.com/advisories/GHSA-4w49-gwv8-fpjg","publishedAt":"2026-10-08T21:57:57.000Z","cveId":"CVE-2026-60091","cweIds":null,"cvssScore":null,"cvssSeverity":"high","severity":"high","attackType":["other"],"issueType":"vulnerability","affectedPackages":["praisonai@<= 4.6.77 (fixed: 4.6.78)"],"affectedPackageNames":["praisonai"],"affectedVendors":[],"affectedVendorsRaw":["PraisonAI"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","summaryPromptVersion":"v2","headline":null,"headlinePromptVersion":null,"cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":"unknown","epssScore":0.00301,"epssCheckedAt":"2026-10-10T03:00:40.088Z","kevDateAdded":null,"advisoryAliases":["GHSA-4w49-gwv8-fpjg"],"affectedPackagesSource":null,"affectedPackagesCheckedAt":null,"patchAvailable":true,"disclosureDate":"2026-10-08T21:57:57.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"moderate","impactType":["confidentiality","integrity"],"aiComponentTargeted":"api","llmSpecific":false,"classifierConfidence":0.9,"researchCategory":null,"atlasIds":["AML.T0010"]}}