THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-5r34-2g38-6569 (high) — praisonaiagents web_crawl vulnerable to SSRF via redirect-following

[GHSA] GHSA-5r34-2g38-6569 (high) — praisonaiagents web_crawl vulnerable to SSRF via redirect-following

highgithub_advisoriesPublished 2026-08-25

GHSA-5r34-2g38-6569 Severity: high CVE: CVE-2026-55525

praisonaiagents web_crawl vulnerable to SSRF via redirect-following

### Summary `web_crawl` (an exported, model-callable tool) validates only the INITIAL URL's resolved IP against a private/loopback blocklist, then fetches with `httpx.Client(follow_redirects=True)` and never re-validates redirect targets.

An attacker who controls the agent

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-5r34-2g38-6569