Vulnerability  ·  2026-09-15

PraisonAI — additional agentic-tool authz/path/SSRF weaknesses (secondary cluster)

VulnerabilityMedium impactGlobalCVE-2026-57126
These extend the same-day PraisonAI critical cluster into agent tool-call surfaces (web scraping, email, code execution, file access) reachable directly from LLM-generated arguments — classic agentic attack surface where prompt-influenced input reaches OS/network primitives without workspace or credential boundaries.
A second cluster of high/medium PraisonAI CVEs disclosed 2026-09-14: CVE-2026-57126 (SSRF via DNS-rebind in SpiderTools web-fetch tool, CVSS 8.5), CVE-2026-57130 (IMAP SEARCH command injection via unsanitized LLM-controlled fields, CVSS 8.1), CVE-2026-57119/57129/56839 (path traversal in Jobs API file argument, mention-parser file resolution, and code-read/search tools respectively, CVSS 7.3–7.5), CVE-2026-57132 (opt-out auth bypass on /api/v1/agents/{id}/invoke, CVSS 8.2), CVE-2026-57115 (SSRF via redirect in scrape_page), CVE-2026-57120 (sandbox escape in execute_code via dunder/format-string attribute access), and CVE-2026-57128 (unauthenticated SSE broadcast/publish endpoint).
praisonaiagents < 1.6.59 (SpiderTools, MentionsParser, CODE_TOOLS, email_tools, execute_code sandbox, SSE server)
Upgrade to praisonaiagents 1.6.59 (or 1.6.58 for the SSE/sandbox issues); see individual GHSA advisories linked from each CVE for exact patched versions.
NVD CVE-2026-57126PraisonAI commit
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →