HighVulnerability
GHSA-4w49-gwv8-fpjg: PraisonAI: Jobs API is unauthenticated by default and allows attacker-controlled webhook SSRF
- Identifiers
- CVE-2026-60091GHSA-4w49-gwv8-fpjg
- Published
- Record updated
Summary
PraisonAI's Async Jobs API enables API-key middleware only when PRAISONAI_JOBS_API_KEY is set, so all endpoints are unauthenticated by default. An unauthenticated POST /api/v1/runs accepts an attacker-controlled webhook_url, and the server POSTs job payloads to it via httpx, with a DNS-rebinding bypass of the request-time SSRF check that reaches internal services as a blind SSRF.
Mitigation
The source does not state a fix yet. Check the original advisory for updates.
Related items
- CriticalCVE-2026-108263: Astron Agent is an agentic workflow platform for building and running AI agents. Prior to 1.1.2, the default workflow coSimilar attack · NVD/CVE Database
- MediumHackers abuse Google Ads, Bing redirects to push Claude ClickFix attacksSimilar attack · BleepingComputer
- LowSocial Engineering AI Agents: The New BEC for 2026Similar attack · Dark Reading
- HighGHSA-cv3g-hj65-pcfh: PraisonAI: Shell command allowlist bypass via find -exec built-in actionSimilar attack · GitHub Advisory Database
- CriticalGHSA-9mp3-24cc-77mg: PraisonAI: AICoder Arbitrary File Write and Command Execution via LLM Tool CallsSimilar attack · GitHub Advisory Database