THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-vg6p-v9vm-6fgj (high) — praisonaiagents vulnerable to SSRF in web_crawl tool via redirect-following and DNS rebinding (validate-then-fetch gap)

[GHSA] GHSA-vg6p-v9vm-6fgj (high) — praisonaiagents vulnerable to SSRF in web_crawl tool via redirect-following and DNS rebinding (validate-then-fetch gap)

highgithub_advisoriesPublished 2026-08-25

GHSA-vg6p-v9vm-6fgj Severity: high CVE: CVE-2026-55524

praisonaiagents vulnerable to SSRF in web_crawl tool via redirect-following and DNS rebinding (validate-then-fetch gap)

The web_crawl tool performs its SSRF check only on the initial URL: it resolves the hostname once with socket.gethostbyname and rejects private/loopback/link-local results. It then passes the URL to a fetcher that uses http

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-vg6p-v9vm-6fgj