GHSA-5r34-2g38-6569: praisonaiagents web_crawl vulnerable to SSRF via redirect-following
highvulnerability
security
Summary
The `web_crawl` tool in praisonaiagents only validates the initial URL's IP address against a blocklist of private/internal addresses, but then follows HTTP redirects without re-checking the redirect target's IP. An attacker can supply a public URL that redirects to an internal address (like cloud metadata services at 169.254.169.254 or localhost services), allowing the tool to fetch and leak internal data that should have been blocked by SSRF (server-side request forgery, where a tool fetches data from internal systems it shouldn't access) protection.
Vulnerability Details
EPSS (30-day exploit probability)
EPSS: 0.0%
Patch Available
Yes
Disclosure Date
August 25, 2026
Classification
Attack SophisticationModerate
Impact (CIA+S)
confidentialityintegrity
AI Component TargetedAgent
Affected Vendors
Affected Packages
praisonaiagents@< 1.6.58 (fixed: 1.6.58)
Monthly digest — independent AI security research
Original source: https://github.com/advisories/GHSA-5r34-2g38-6569
First tracked: August 25, 2026 at 02:01 PM
Classified by LLM (prompt v3) · confidence: 95%