<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 10:34:14 +0000</lastBuildDate>
    <item>
      <title>CVE-2026-55537 — PraisonAI: Webhook SSRF via DNS fail-open in `JobSubmitRequest.validate_webhook_url()` — bypass of CVE-2026-40114</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2026-55537</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; MervinPraison PraisonAI&lt;/p&gt;
&lt;p&gt;PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.58, JobSubmitRequest.validate_webhook_url() accepts webhook_url when resolution raises socket.gaierror because the exception path uses except socket.gaierror: pass. JobExecutor._send_webhook() later performs a fresh lookup, allowing DNS changes to direct the request to an internal service. This issue is fixed in version 4.6.58.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; MervinPraison PraisonAI&lt;/p&gt;
&lt;p&gt;PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.58, JobSubmitRequest.validate_webhook_url() accepts webhook_url when resolution raises socket.gaierror because the exception path uses except socket.gaierror: pass. JobExecutor._send_webhook() later performs a fresh lookup, allowing DNS changes to direct the request to an internal service. This issue is fixed in version 4.6.58.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2026-55537</guid>
    </item>
    <item>
      <title>GHSA-rg5q-pp8p-f7jm — PraisonAI: Webhook SSRF via DNS fail-open in `JobSubmitRequest.validate_webhook_url()` — bypass of CVE-2026-40114</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-rg5q-pp8p-f7jm</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: PraisonAI&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;`praisonai/jobs/models.py::JobSubmitRequest.validate_webhook_url()` validates webhook
URLs by resolving the hostname and checking whether the IP is private. When DNS
resolution fails (`socket.gaierror`), the validator **silently passes** the URL via
`except socket.gaierror: pass`. Additionally, even when DNS succeeds at validation time,
the webhook is fired much later by `JobExecutor._send_webhook()`, which calls
`httpx.AsyncClient().post(job.webhook_url)` — performing a **fresh, independent DNS
lookup** at execution time. Together, these flaws create a TOCTOU SSRF window.&lt;/p&gt;
&lt;p&gt;An attacker can:
1. Submit a job with `webhook_url` pointing to a hostname that currently does not
   resolve (NXDOMAIN) → validation passes (`gaierror` → `pass`)
2. Update DNS to point that hostname to `127.0.0.1` or another private IP
3. When the job completes, `_send_webhook()` resolves the hostname fresh → POST sent
   to the internal IP&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;**Flaw 1 — Fail-open on DNS error (`jobs/models.py` lines 58-66):**&lt;/p&gt;
&lt;p&gt;```python
@field_validator(&amp;#34;webhook_url&amp;#34;)
@classmethod
def validate_webhook_url(cls, v):
    ...
    try:
        ip = socket.gethostbyname(hostname)
        ip_obj = ipaddress.ip_address(ip)
        if ip_obj.is_private or ip_obj.is_loopback or ip_obj.is_link_local:
            raise ValueError(&amp;#34;Webhook URL resolves to private network address&amp;#34;)
    except socket.gaierror:
        pass    # &amp;lt;-- FAIL-OPEN: DNS failure allows the URL without restriction
    return v
```&lt;/p&gt;
&lt;p&gt;When…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: PraisonAI&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;`praisonai/jobs/models.py::JobSubmitRequest.validate_webhook_url()` validates webhook
URLs by resolving the hostname and checking whether the IP is private. When DNS
resolution fails (`socket.gaierror`), the validator **silently passes** the URL via
`except socket.gaierror: pass`. Additionally, even when DNS succeeds at validation time,
the webhook is fired much later by `JobExecutor._send_webhook()`, which calls
`httpx.AsyncClient().post(job.webhook_url)` — performing a **fresh, independent DNS
lookup** at execution time. Together, these flaws create a TOCTOU SSRF window.&lt;/p&gt;
&lt;p&gt;An attacker can:
1. Submit a job with `webhook_url` pointing to a hostname that currently does not
   resolve (NXDOMAIN) → validation passes (`gaierror` → `pass`)
2. Update DNS to point that hostname to `127.0.0.1` or another private IP
3. When the job completes, `_send_webhook()` resolves the hostname fresh → POST sent
   to the internal IP&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;**Flaw 1 — Fail-open on DNS error (`jobs/models.py` lines 58-66):**&lt;/p&gt;
&lt;p&gt;```python
@field_validator(&amp;#34;webhook_url&amp;#34;)
@classmethod
def validate_webhook_url(cls, v):
    ...
    try:
        ip = socket.gethostbyname(hostname)
        ip_obj = ipaddress.ip_address(ip)
        if ip_obj.is_private or ip_obj.is_loopback or ip_obj.is_link_local:
            raise ValueError(&amp;#34;Webhook URL resolves to private network address&amp;#34;)
    except socket.gaierror:
        pass    # &amp;lt;-- FAIL-OPEN: DNS failure allows the URL without restriction
    return v
```&lt;/p&gt;
&lt;p&gt;When…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-rg5q-pp8p-f7jm</guid>
    </item>
  </channel>
</rss>
