PraisonAI vulnerable to Server-Side Request Forgery via DNS rebinding bypass in webhook_url validation
PYSEC-2026-3890 · CVE-2026-55535 · GHSA-hmfx-4v44-9qw9
Published · Modified
AI SAST
Find this class of vulnerability in your own code
Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.
Description
Summary
The webhook_url field in the Jobs API silently passes validation when DNS resolution fails (socket.gaierror), enabling DNS rebinding attacks. An attacker's domain can initially resolve to a public IP (passing validation) then switch to an internal IP before the server makes the HTTP request.
Details
The validator catches socket.gaierror and silently allows the URL:
# src/praisonai/praisonai/jobs/models.py:55
try:
ip = socket.gethostbyname(hostname)
ip_obj = ipaddress.ip_address(ip)
if ip_obj.is_private or ip_obj.is_loopback:
raise ValueError("private address")
except socket.gaierror:
pass # BUG: DNS failure silently ignored → SSRF bypass
The HTTP call is made later with no re-validation:
# src/praisonai/praisonai/jobs/executor.py:402
async with httpx.AsyncClient() as client:
await client.post(job.webhook_url, ...) # no second IP check
Proof of Concept
DNS rebinding flow:
- Register
attacker.comwith TTL=1s → resolves to1.2.3.4(public IP) - Submit job:
webhook_url=http://attacker.com/callback - Validation passes (public IP)
- Switch DNS:
attacker.com→127.0.0.1 - Job completes → server POSTs to
127.0.0.1→ internal SSRF
Unresolvable domain bypass (no DNS rebinding required):
curl -X POST http://:8005/api/v1/runs \
-d '{"prompt":"run","webhook_url":"http://unresolvable.internal/cb","agent_yaml":"..."}'
# Validation: gaierror → pass → URL accepted
Impact
SSRF to internal HTTP services: admin panels, databases, and cloud metadata APIs (e.g., http://169.254.169.254/). Exploitable without authentication.
References
- WEB https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-hmfx-4v44-9qw9
- WEB https://github.com/MervinPraison/PraisonAI/commit/2f9677abb2ea68eab864ee8b6a828fd0141612e1
- PACKAGE https://github.com/MervinPraison/PraisonAI
- WEB https://github.com/MervinPraison/PraisonAI/releases/tag/v4.6.58
- PACKAGE https://pypi.org/project/praisonai
- ADVISORY https://github.com/advisories/GHSA-hmfx-4v44-9qw9
- ADVISORY https://nvd.nist.gov/vuln/detail/CVE-2026-55535
Ready to move
Start Securing
Free, no credit card | First findings in minutes