<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T15:05:31.196402+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2026-55537</id>
    <title>CVE-2026-55537 — PraisonAI: Webhook SSRF via DNS fail-open in `JobSubmitRequest.validate_webhook_url()` — bypass of CVE-2026-40114</title>
    <updated>2026-10-03T15:05:31.226091+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> MervinPraison PraisonAI</p>
<p>PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.58, JobSubmitRequest.validate_webhook_url() accepts webhook_url when resolution raises socket.gaierror because the exception path uses except socket.gaierror: pass. JobExecutor._send_webhook() later performs a fresh lookup, allowing DNS changes to direct the request to an internal service. This issue is fixed in version 4.6.58.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2026-55537"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-rg5q-pp8p-f7jm</id>
    <title>GHSA-rg5q-pp8p-f7jm — PraisonAI: Webhook SSRF via DNS fail-open in `JobSubmitRequest.validate_webhook_url()` — bypass of CVE-2026-40114</title>
    <updated>2026-10-03T15:05:31.226154+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: PraisonAI</p>
<p>### Summary</p>
<p>`praisonai/jobs/models.py::JobSubmitRequest.validate_webhook_url()` validates webhook
URLs by resolving the hostname and checking whether the IP is private. When DNS
resolution fails (`socket.gaierror`), the validator **silently passes** the URL via
`except socket.gaierror: pass`. Additionally, even when DNS succeeds at validation time,
the webhook is fired much later by `JobExecutor._send_webhook()`, which calls
`httpx.AsyncClient().post(job.webhook_url)` — performing a **fresh, independent DNS
lookup** at execution time. Together, these flaws create a TOCTOU SSRF window.</p>
<p>An attacker can:
1. Submit a job with `webhook_url` pointing to a hostname that currently does not
   resolve (NXDOMAIN) → validation passes (`gaierror` → `pass`)
2. Update DNS to point that hostname to `127.0.0.1` or another private IP
3. When the job completes, `_send_webhook()` resolves the hostname fresh → POST sent
   to the internal IP</p>
<p>### Details</p>
<p>**Flaw 1 — Fail-open on DNS error (`jobs/models.py` lines 58-66):**</p>
<p>```python
@field_validator("webhook_url")
@classmethod
def validate_webhook_url(cls, v):
    ...
    try:
        ip = socket.gethostbyname(hostname)
        ip_obj = ipaddress.ip_address(ip)
        if ip_obj.is_private or ip_obj.is_loopback or ip_obj.is_link_local:
            raise ValueError("Webhook URL resolves to private network address")
    except socket.gaierror:
        pass    # &lt;-- FAIL-OPEN: DNS failure allows the URL without restriction
    return v
```</p>
<p>When…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-rg5q-pp8p-f7jm"/>
  </entry>
</feed>
