CVE-2026-61429 Details
Description
PraisonAI versions before 1.6.78 contain a server-side request forgery vulnerability in the Crawl4AI/Chromium backend that allows attackers to bypass SSRF validation by exploiting DNS rebinding and HTTP redirects. Attackers can craft URLs that resolve to internal services after the initial validation check, enabling the headless browser to follow redirects and read internal responses including sensitive canary values.
A server-side request forgery (SSRF) vulnerability has been identified in PraisonAI versions prior to 1.6.78, specifically within the Crawl4AI/Chromium backend. This vulnerability allows attackers to bypass SSRF validation by exploiting DNS rebinding and HTTP redirects. Attackers can craft URLs that initially pass validation but later resolve to internal services, enabling the headless browser to follow redirects and access internal responses, including sensitive canary values.
Users are advised to update to PraisonAI version 1.6.78 or later. Additionally, ensure that the SSRF validation includes a per-connection check and IP pinning for the Crawl4AI backend.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jul 11, 2026CISA-ADP
Assessed Jul 13, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-6g59-gm2v-qhvq | CISA-ADP | AdvisoryExploitTechnical AnalysisVendor |
| https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-6g59-gm2v-qhvq | [email protected] | AdvisoryExploitTechnical AnalysisVendor |
| https://www.vulncheck.com/advisories/praisonai-before-ssrf-via-crawl4ai-chromium-backend | [email protected] | Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-918 | Server-Side Request Forgery (SSRF) | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| PraisonAI | <= 1.6.77 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 13, 2026 | CVE Modified | CISA-ADP |
| Jul 11, 2026 | New CVE Received | [email protected] |
Volerion