THREAT OPS › Threat News › [GHSA] GHSA-hmfx-4v44-9qw9 (medium) — PraisonAI vulnerable to Server-Side Request Forgery via DNS rebinding bypass in webhook_url validation
[GHSA] GHSA-hmfx-4v44-9qw9 (medium) — PraisonAI vulnerable to Server-Side Request Forgery via DNS rebinding bypass in webhook_url validation
GHSA-hmfx-4v44-9qw9 Severity: medium CVE: CVE-2026-55535
PraisonAI vulnerable to Server-Side Request Forgery via DNS rebinding bypass in webhook_url validation
### Summary The `webhook_url` field in the Jobs API silently passes validation when DNS resolution fails (`socket.gaierror`), enabling DNS rebinding attacks. An attacker's domain can initially resolve to a public IP (passing validation) t
Indicators of compromise
- CVE-2026-55535cve
- http://attacker.com/callback`url
- http://unresolvable.internal/cburl
- http://169.254.169.254/`url
- 1.2.3.4ipv4
Original source: https://github.com/advisories/GHSA-hmfx-4v44-9qw9