CPE
high
advisory
Insecure Default Configuration in PraisonAI Allows Unauthenticated Access
2 rules 3 TTPs 1 CVEAn insecure default configuration in PraisonAI before version 1.7.3 allows unauthenticated attackers to exploit CVE-2026-61426 by reading sensitive agent instructions and system prompts via the `/api/agents` endpoint and invoking agents without authentication through the `/api/chat` endpoint, leading to unauthorized information disclosure and potential control over AI functionalities.
PoC
PraisonAI
vulnerability
web-application
insecure-configuration
cve
2r
3t
1c
updated
high
advisory
Unauthenticated Server-Side Request Forgery in PraisonAI Jobs API (CVE-2026-60091)
2 TTPs 1 CVEPraisonAI versions before 4.6.78 contain an unauthenticated server-side request forgery (SSRF) vulnerability, CVE-2026-60091, in the Jobs API `/api/v1/runs` endpoint via the `webhook_url` parameter, allowing attackers to exploit DNS rebinding to access internal services.
PoC
PraisonAI
vulnerability
ssrf
dns-rebinding
2t
1c
updated