Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-57115

Опубликовано: 14 сент. 2026
Источник: nvd
CVSS3: 6.5
EPSS Низкий

Описание

PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.59, SpiderTools.scrape_page validates only the initial URL and lets requests.Session.get follow redirects automatically, so a public-looking URL can redirect to a loopback, private, link-local, or metadata address without revalidation. The redirected response body is returned through scrape_page and its extract_links, crawl, and extract_text callers, allowing disclosure from otherwise blocked services. This issue is fixed in praisonaiagents 1.6.59.

EPSS

Процентиль: 18%
0.00257
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-918

Связанные уязвимости

CVSS3: 6.5
github
3 месяца назад

PraisonAI: SpiderTools redirect-target SSRF protection bypass

EPSS

Процентиль: 18%
0.00257
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-918