Project Subscriptions
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-8frj-8q3m-xhgm | PraisonAI Vulnerable to Server-Side Request Forgery via Unvalidated webhook_url in Jobs API |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Fri, 17 Apr 2026 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Praison
Praison praisonai |
|
| CPEs | cpe:2.3:a:praison:praisonai:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Praison
Praison praisonai |
Mon, 13 Apr 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 10 Apr 2026 09:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mervinpraison
Mervinpraison praisonai |
|
| Vendors & Products |
Mervinpraison
Mervinpraison praisonai |
Thu, 09 Apr 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | PraisonAI is a multi-agent teams system. Prior to 4.5.128, the /api/v1/runs endpoint accepts an arbitrary webhook_url in the request body with no URL validation. When a submitted job completes (success or failure), the server makes an HTTP POST request to this URL using httpx.AsyncClient. An unauthenticated attacker can use this to make the server send POST requests to arbitrary internal or external destinations, enabling SSRF against cloud metadata services, internal APIs, and other network-adjacent services. This vulnerability is fixed in 4.5.128. | |
| Title | PraisonAI has Server-Side Request Forgery via Unvalidated webhook_url in Jobs API | |
| Weaknesses | CWE-918 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-04-13T20:38:45.906Z
Reserved: 2026-04-09T01:41:38.537Z
Link: CVE-2026-40114
Updated: 2026-04-13T20:38:41.562Z
Status : Analyzed
Published: 2026-04-09T22:16:35.000
Modified: 2026-04-17T18:36:03.437
Link: CVE-2026-40114
No data.
OpenCVE Enrichment
Updated: 2026-04-10T09:28:57Z
Github GHSA