What is CVE-2026-55523?
A server-side request forgery (SSRF) vulnerability exists in the PraisonAI multi-agent system. In versions 1.5.128 through 1.6.57, the `web_crawl()` function validates the initial URL but its default behavior may allow access to internal resources. Apply the update immediately.
Azərbaycanca: PraisonAI multi-agent sistemində server-side request forgery (SSRF) zəifliyi aşkarlanıb. 1.5.128-1.6.57 versiyalarında `web_crawl()` funksiyası ilkin URL-i yoxlasa da, defolt davranışla daxili resurslara giriş mümkündür. Təcili yeniləmə tətbiq edin.
Related CVEs
link basis: same weakness class CWE-918
FAQ2
Which function in PraisonAI is affected by CVE-2026-55523?
The vulnerability is in the `web_crawl()` function.
What versions of PraisonAI are affected by this SSRF vulnerability?
Versions 1.5.128 through 1.6.57 are affected.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.