What is CVE-2026-55524?
In PraisonAI versions prior to 1.6.58, the SSRF check in the web_crawl tool is only applied to the initially supplied URL, allowing attackers to bypass the protection and access internal network resources. Organizations should immediately upgrade and restrict the tool's activity.
Azərbaycanca: PraisonAI sisteminin 1.6.58-dən əvvəlki versiyalarında SSRF yoxlanışı yalnız ilkin URL üzərində aparılır ki, bu da müdafiənin keçilməsinə və daxili şəbəkə resurslarına icazəsiz girişə yol açır. Təşkilatlar dərhal yeni versiyaya yeniləməli və web_crawl alətinin fəaliyyətini məhdudlaşdırmalıdır.
Related CVEs
link basis: same weakness class CWE-918
FAQ2
Which versions of PraisonAI are affected by CVE-2026-55524?
This SSRF vulnerability affects PraisonAI versions prior to 1.6.58.
What measures should organizations take to mitigate CVE-2026-55524?
Organizations should immediately upgrade to version 1.6.58 and restrict the activity of the web_crawl tool.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.