CVE-2026-55537CWE-367CWE-705CWE-918ssrf

CVE-2026-55537

High · published August 25, 2026

CVSS v3.1
7.1
EPSS
0%
Percentile
7.6
In the wild
Unconfirmed
What it is

PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.58, JobSubmitRequest.validate_webhook_url() accepts webhook_url when resolution raises socket.gaierror because the exception path uses except socket.gaierror: pass. JobExecutor._send_webhook() later performs a fresh lookup, allowing DNS changes to direct the request to an internal service. This issue is fixed in version 4.6.58.

The record
Technical detail
CVSS v3.1
7.1 · HIGH
Vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:L/A:N
CVSS v4.0
Not supplied
EPSS
0.00179 · 7.6th percentile
Weaknesses
CWE-367 · Time-of-check Time-of-use (TOCTOU) Race Condition; CWE-705 · Incorrect Control Flow Scoping; CWE-918 · Server-Side Request Forgery (SSRF)
Published
2026-08-25T19:16Z
References (3)
EPSS history
Timeline
  • 27 AUG 06:36Z
    EPSS moved — → 0%
    epss
  • 25 AUG 14:58Z
    PraisonAI: Webhook SSRF via DNS fail-open in `JobSubmitRequest.validate_webhook_url()` — bypass of CVE-2026-40114
    cvelistv5