CVE-2026-60091: PraisonAI before 4.6.78 Unauthenticated SSRF via webhook_url
PraisonAI before 4.6.78 contains an unauthenticated server-side request forgery vulnerability in the Jobs API /api/v1/runs endpoint. The webhookurl parameter is validated at request time but re-resolved at connection time, allowing attackers to use DNS rebinding to reach internal services with a blind SSRF attack.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
PraisonAIto a version that resolves this vulnerability.Fixed in 4.6.78
Event History
Frequently Asked Questions
What is the severity of CVE-2026-60091?
CVE-2026-60091 has a medium severity score of 6.9.
How do I fix CVE-2026-60091?
To mitigate CVE-2026-60091, upgrade to PraisonAI version 4.6.78 or later.
What type of vulnerability is CVE-2026-60091?
CVE-2026-60091 is classified as an unauthenticated server-side request forgery (SSRF) vulnerability.
What components are affected by CVE-2026-60091?
CVE-2026-60091 affects the Jobs API endpoint /api/v1/runs in PraisonAI versions prior to 4.6.78.
Can CVE-2026-60091 be exploited remotely?
Yes, CVE-2026-60091 can be exploited remotely due to its unauthenticated nature.