CVE Explorer
CVE-2026-40160
PraisonAIAgents is a multi-agent teams system. Prior to 1.5.128, web_crawl's httpx fallback path passes user-supplied URLs directly to httpx.AsyncClient.get() with follow_redirects=True and no host validation. An LLM agent tricked into crawling an internal URL can reach cloud metadata endpoints (169.254.169.254), internal services, and localhost. The response content is returned to the agent and may appear in output visible to the attacker. This fallback is the default crawl path on a fresh Prai
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"PraisonAIAgents","vendor":"MervinPraison","versions":[{"status":"affected","version":"< 1.5.128"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:261226a8e9ab6225cac499d0e24927515ba4d6bce27442b908baa110e30e6eaa · sha256:be2e3886d0179bb3… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackRequirements":"PRESENT","attackVector":"NETWORK","baseScore":7.1,"baseSeverity":"HIGH","privilegesRequired":"NONE","subAvailabilityImpact":"NONE","subConfidentialityImpact":"HIGH","subIntegrityImpact":"LOW","userInteraction":"PASSIVE","vectorString":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:N/VA:N/SC:H/SI:L/SA:N","version":"4.0","vulnAvailabilityImpact":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"NONE"},"metric_type":"cvssV4_0"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:261226a8e9ab6225cac499d0e24927515ba4d6bce27442b908baa110e30e6eaa · sha256:be2e3886d0179bb3… · /containers/cna/metrics/0/cvssV4_0
CWE assertions
1 source assertion{"cweId":"CWE-918","description":"CWE-918: Server-Side Request Forgery (SSRF)","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:261226a8e9ab6225cac499d0e24927515ba4d6bce27442b908baa110e30e6eaa · sha256:be2e3886d0179bb3… · /containers/cna/problemTypes/0/descriptions/0
Source references
2 source assertions{"tags":["exploit"],"url":"https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-qq9r-63f6-v542"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:261226a8e9ab6225cac499d0e24927515ba4d6bce27442b908baa110e30e6eaa · sha256:be2e3886d0179bb3… · /containers/adp/0/references/0
{"name":"https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-qq9r-63f6-v542","tags":["x_refsource_CONFIRM"],"url":"https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-qq9r-63f6-v542"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:261226a8e9ab6225cac499d0e24927515ba4d6bce27442b908baa110e30e6eaa · sha256:be2e3886d0179bb3… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.