Описание
PraisonAI before 1.6.78 contains a server-side request forgery vulnerability in the web_crawl tool that validates hostnames at check time but re-resolves them at connection time without IP pinning. Attackers can use DNS rebinding to bypass SSRF protection and retrieve internal HTTP response bodies from private or loopback services.
EPSS
Процентиль: 11%
0.00205
Низкий
8.5 High
CVSS3
Дефекты
CWE-918
Связанные уязвимости
CVSS3: 8.5
github
около 1 месяца назад
PraisonAI before 1.6.78 contains a server-side request forgery vulnerability in the web_crawl tool that validates hostnames at check time but re-resolves them at connection time without IP pinning. Attackers can use DNS rebinding to bypass SSRF protection and retrieve internal HTTP response bodies from private or loopback services.
EPSS
Процентиль: 11%
0.00205
Низкий
8.5 High
CVSS3
Дефекты
CWE-918