<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 05:17:12 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-290873</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-290873</link>
      <description>EUVD-2026-290873</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-290873</guid>
    </item>
    <item>
      <title>fkie_cve-2026-40160</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-40160</link>
      <description>&lt;p&gt;PraisonAIAgents is a multi-agent teams system. Prior to 1.5.128, web_crawl&amp;#39;s httpx fallback path passes user-supplied URLs directly to httpx.AsyncClient.get() with follow_redirects=True and no host validation. An LLM agent tricked into crawling an internal URL can reach cloud metadata endpoints (169.254.169.254), internal services, and localhost. The response content is returned to the agent and may appear in output visible to the attacker. This fallback is the default crawl path on a fresh PraisonAI installation (no Tavily key, no Crawl4AI installed). This vulnerability is fixed in 1.5.128.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;PraisonAIAgents is a multi-agent teams system. Prior to 1.5.128, web_crawl&amp;#39;s httpx fallback path passes user-supplied URLs directly to httpx.AsyncClient.get() with follow_redirects=True and no host validation. An LLM agent tricked into crawling an internal URL can reach cloud metadata endpoints (169.254.169.254), internal services, and localhost. The response content is returned to the agent and may appear in output visible to the attacker. This fallback is the default crawl path on a fresh PraisonAI installation (no Tavily key, no Crawl4AI installed). This vulnerability is fixed in 1.5.128.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-40160</guid>
    </item>
    <item>
      <title>GHSA-qq9r-63f6-v542 — PraisonAIAgents: SSRF via unvalidated URL in `web_crawl` httpx fallback</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-qq9r-63f6-v542</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: praisonaiagents&lt;/p&gt;
&lt;p&gt;| Field | Value |
|---|---|
| Severity | High |
| Type | SSRF -- unvalidated URL in `web_crawl` httpx fallback allows internal network access |
| Affected | `src/praisonai-agents/praisonaiagents/tools/web_crawl_tools.py:133-180` |&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;`web_crawl`&amp;#39;s httpx fallback path passes user-supplied URLs directly to `httpx.AsyncClient.get()` with `follow_redirects=True` and no host validation. An LLM agent tricked into crawling an internal URL can reach cloud metadata endpoints (`169.254.169.254`), internal services, and localhost. The response content is returned to the agent and may appear in output visible to the attacker.&lt;/p&gt;
&lt;p&gt;This fallback is the default crawl path on a fresh PraisonAI installation (no Tavily key, no Crawl4AI installed).&lt;/p&gt;
&lt;p&gt;## Details&lt;/p&gt;
&lt;p&gt;The vulnerable code is in `tools/web_crawl_tools.py:148-155`:&lt;/p&gt;
&lt;p&gt;```python
async with httpx.AsyncClient(
    follow_redirects=True,
    timeout=httpx.Timeout(30)
) as client:
    response = await client.get(url)  # url from agent tool call, no validation
```&lt;/p&gt;
&lt;p&gt;No scheme restriction, no hostname resolution, no private/link-local IP check. `follow_redirects=True` also means an attacker can use an open redirect on a public URL to bounce the request into internal networks.&lt;/p&gt;
&lt;p&gt;`download_file` in `file_tools.py:295-318`, by contrast, validates URLs before requesting:&lt;/p&gt;
&lt;p&gt;```python
parsed = urllib.parse.urlsplit(url)
if parsed.scheme not in (&amp;#34;http&amp;#34;, &amp;#34;https&amp;#34;):
    return &amp;#34;Error: Only HTTP(S) URLs are allowed&amp;#34;
hostname = parsed.hostname
addr = ip…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: praisonaiagents&lt;/p&gt;
&lt;p&gt;| Field | Value |
|---|---|
| Severity | High |
| Type | SSRF -- unvalidated URL in `web_crawl` httpx fallback allows internal network access |
| Affected | `src/praisonai-agents/praisonaiagents/tools/web_crawl_tools.py:133-180` |&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;`web_crawl`&amp;#39;s httpx fallback path passes user-supplied URLs directly to `httpx.AsyncClient.get()` with `follow_redirects=True` and no host validation. An LLM agent tricked into crawling an internal URL can reach cloud metadata endpoints (`169.254.169.254`), internal services, and localhost. The response content is returned to the agent and may appear in output visible to the attacker.&lt;/p&gt;
&lt;p&gt;This fallback is the default crawl path on a fresh PraisonAI installation (no Tavily key, no Crawl4AI installed).&lt;/p&gt;
&lt;p&gt;## Details&lt;/p&gt;
&lt;p&gt;The vulnerable code is in `tools/web_crawl_tools.py:148-155`:&lt;/p&gt;
&lt;p&gt;```python
async with httpx.AsyncClient(
    follow_redirects=True,
    timeout=httpx.Timeout(30)
) as client:
    response = await client.get(url)  # url from agent tool call, no validation
```&lt;/p&gt;
&lt;p&gt;No scheme restriction, no hostname resolution, no private/link-local IP check. `follow_redirects=True` also means an attacker can use an open redirect on a public URL to bounce the request into internal networks.&lt;/p&gt;
&lt;p&gt;`download_file` in `file_tools.py:295-318`, by contrast, validates URLs before requesting:&lt;/p&gt;
&lt;p&gt;```python
parsed = urllib.parse.urlsplit(url)
if parsed.scheme not in (&amp;#34;http&amp;#34;, &amp;#34;https&amp;#34;):
    return &amp;#34;Error: Only HTTP(S) URLs are allowed&amp;#34;
hostname = parsed.hostname
addr = ip…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-qq9r-63f6-v542</guid>
    </item>
    <item>
      <title>PYSEC-2026-2951 — PraisonAIAgents: SSRF via unvalidated URL in `web_crawl` httpx fallback</title>
      <link>https://cve.radiocsirt.org/vuln/pysec-2026-2951</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: praisonaiagents&lt;/p&gt;
&lt;p&gt;| Field | Value |
|---|---|
| Severity | High |
| Type | SSRF -- unvalidated URL in `web_crawl` httpx fallback allows internal network access |
| Affected | `src/praisonai-agents/praisonaiagents/tools/web_crawl_tools.py:133-180` |&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;`web_crawl`&amp;#39;s httpx fallback path passes user-supplied URLs directly to `httpx.AsyncClient.get()` with `follow_redirects=True` and no host validation. An LLM agent tricked into crawling an internal URL can reach cloud metadata endpoints (`169.254.169.254`), internal services, and localhost. The response content is returned to the agent and may appear in output visible to the attacker.&lt;/p&gt;
&lt;p&gt;This fallback is the default crawl path on a fresh PraisonAI installation (no Tavily key, no Crawl4AI installed).&lt;/p&gt;
&lt;p&gt;## Details&lt;/p&gt;
&lt;p&gt;The vulnerable code is in `tools/web_crawl_tools.py:148-155`:&lt;/p&gt;
&lt;p&gt;```python
async with httpx.AsyncClient(
    follow_redirects=True,
    timeout=httpx.Timeout(30)
) as client:
    response = await client.get(url)  # url from agent tool call, no validation
```&lt;/p&gt;
&lt;p&gt;No scheme restriction, no hostname resolution, no private/link-local IP check. `follow_redirects=True` also means an attacker can use an open redirect on a public URL to bounce the request into internal networks.&lt;/p&gt;
&lt;p&gt;`download_file` in `file_tools.py:295-318`, by contrast, validates URLs before requesting:&lt;/p&gt;
&lt;p&gt;```python
parsed = urllib.parse.urlsplit(url)
if parsed.scheme not in (&amp;#34;http&amp;#34;, &amp;#34;https&amp;#34;):
    return &amp;#34;Error: Only HTTP(S) URLs are allowed&amp;#34;
hostname = parsed.hostname
addr = ip…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: praisonaiagents&lt;/p&gt;
&lt;p&gt;| Field | Value |
|---|---|
| Severity | High |
| Type | SSRF -- unvalidated URL in `web_crawl` httpx fallback allows internal network access |
| Affected | `src/praisonai-agents/praisonaiagents/tools/web_crawl_tools.py:133-180` |&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;`web_crawl`&amp;#39;s httpx fallback path passes user-supplied URLs directly to `httpx.AsyncClient.get()` with `follow_redirects=True` and no host validation. An LLM agent tricked into crawling an internal URL can reach cloud metadata endpoints (`169.254.169.254`), internal services, and localhost. The response content is returned to the agent and may appear in output visible to the attacker.&lt;/p&gt;
&lt;p&gt;This fallback is the default crawl path on a fresh PraisonAI installation (no Tavily key, no Crawl4AI installed).&lt;/p&gt;
&lt;p&gt;## Details&lt;/p&gt;
&lt;p&gt;The vulnerable code is in `tools/web_crawl_tools.py:148-155`:&lt;/p&gt;
&lt;p&gt;```python
async with httpx.AsyncClient(
    follow_redirects=True,
    timeout=httpx.Timeout(30)
) as client:
    response = await client.get(url)  # url from agent tool call, no validation
```&lt;/p&gt;
&lt;p&gt;No scheme restriction, no hostname resolution, no private/link-local IP check. `follow_redirects=True` also means an attacker can use an open redirect on a public URL to bounce the request into internal networks.&lt;/p&gt;
&lt;p&gt;`download_file` in `file_tools.py:295-318`, by contrast, validates URLs before requesting:&lt;/p&gt;
&lt;p&gt;```python
parsed = urllib.parse.urlsplit(url)
if parsed.scheme not in (&amp;#34;http&amp;#34;, &amp;#34;https&amp;#34;):
    return &amp;#34;Error: Only HTTP(S) URLs are allowed&amp;#34;
hostname = parsed.hostname
addr = ip…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/pysec-2026-2951</guid>
    </item>
  </channel>
</rss>
