CVE-2026-61430: PraisonAI before 1.6.78 DNS Rebinding SSRF via web_crawl
PraisonAI before 1.6.78 contains a server-side request forgery vulnerability in the webcrawl tool that validates hostnames at check time but re-resolves them at connection time without IP pinning. Attackers can use DNS rebinding to bypass SSRF protection and retrieve internal HTTP response bodies from private or loopback services.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
PraisonAI web_crawlto a version that resolves this vulnerability.Fixed in 1.6.78
Event History
Frequently Asked Questions
What is the severity of CVE-2026-61430?
CVE-2026-61430 has a severity rating of 8.4, categorized as high risk.
How do I fix CVE-2026-61430?
To remediate CVE-2026-61430, upgrade PraisonAI to version 1.6.78 or later.
What is the impact of CVE-2026-61430?
CVE-2026-61430 allows attackers to exploit DNS rebinding to bypass SSRF protections and access internal server information.
Which software is affected by CVE-2026-61430?
CVE-2026-61430 affects versions of PraisonAI prior to 1.6.78.
What type of vulnerability is CVE-2026-61430?
CVE-2026-61430 is classified as a server-side request forgery (SSRF) vulnerability.