<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:mervinpraison:praisonai:*:*:*:*:*:*:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3amervinpraisonpraisonai/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Sat, 11 Jul 2026 14:21:33 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3amervinpraisonpraisonai/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Insecure Default Configuration in PraisonAI Allows Unauthenticated Access</title><link>https://feed.craftedsignal.io/briefs/2026-07-praisonai-insecure-config/</link><pubDate>Sat, 11 Jul 2026 14:21:33 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-07-praisonai-insecure-config/</guid><description>An insecure default configuration in PraisonAI before version 1.7.3 allows unauthenticated attackers to exploit CVE-2026-61426 by reading sensitive agent instructions and system prompts via the `/api/agents` endpoint and invoking agents without authentication through the `/api/chat` endpoint, leading to unauthorized information disclosure and potential control over AI functionalities.</description><content:encoded><![CDATA[<p>CVE-2026-61426 details a critical security vulnerability in PraisonAI software versions prior to 1.7.3. The vulnerability stems from an insecure default configuration where the application binds to all network interfaces without requiring API keys for sensitive operations and utilizes a wildcard CORS policy. This flaw permits unauthenticated attackers to make direct HTTP requests to internal API endpoints. Specifically, attackers can issue a GET request to <code>/api/agents</code> to retrieve confidential agent instructions and system prompts, effectively exposing proprietary logic and sensitive data. Furthermore, the absence of authentication allows attackers to send POST requests to <code>/api/chat</code>, enabling them to invoke agents and interact with the AI functionalities without authorization. This vulnerability has a CVSS v3.1 base score of 8.6 (High), highlighting its significant risk. Organizations utilizing PraisonAI instances, particularly those exposed to the internet, are at risk of unauthorized access, intellectual property theft, and potential misuse of their AI agents.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li><strong>Discovery of Public-Facing PraisonAI Instance</strong>: An unauthenticated attacker scans for internet-exposed PraisonAI instances, identifying applications running vulnerable versions.</li>
<li><strong>Unauthenticated Information Gathering (GET /api/agents)</strong>: The attacker sends an unauthenticated HTTP GET request to the <code>/api/agents</code> endpoint of the vulnerable PraisonAI application.</li>
<li><strong>Sensitive Information Exposure</strong>: Due to the insecure default configuration (no API key requirement and wildcard CORS), the PraisonAI instance responds with agent instructions and system prompts, disclosing sensitive internal configuration and AI logic.</li>
<li><strong>Unauthenticated Agent Invocation (POST /api/chat)</strong>: Leveraging the absence of authentication, the attacker then crafts and sends an unauthenticated HTTP POST request to the <code>/api/chat</code> endpoint.</li>
<li><strong>Unauthorized Agent Operation</strong>: The PraisonAI application processes the POST request without validating user credentials, allowing the attacker to invoke and interact with AI agents, potentially leading to unauthorized operations or manipulation of AI services.</li>
</ol>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of CVE-2026-61426 leads to severe consequences, primarily unauthorized access to sensitive information and control over AI functionalities. Attackers can exfiltrate proprietary agent instructions and system prompts, which could contain business logic, trade secrets, or data handling methodologies. This exposure can lead to intellectual property theft or provide attackers with insights to further compromise the system. Additionally, the ability to invoke agents without authentication means an attacker can misuse AI resources, potentially consuming computational resources, generating malicious content, or interacting with other systems the AI agents are authorized to access. While no specific victim counts are provided, any organization running an unpatched PraisonAI instance with public exposure is at high risk.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li><strong>Patch CVE-2026-61426</strong>: Immediately update all PraisonAI instances to version 1.7.3 or higher to address the insecure default configuration.</li>
<li><strong>Deploy Detection Rules</strong>: Deploy the provided Sigma rules (<code>Detects CVE-2026-61426 Exploitation - GET /api/agents</code> and <code>Detects CVE-2026-61426 Exploitation - POST /api/chat</code>) to your SIEM to detect exploitation attempts.</li>
<li><strong>Review Network Exposure</strong>: Configure network firewalls and access controls to restrict direct internet access to PraisonAI instances, particularly on sensitive API endpoints.</li>
<li><strong>Enable Web Server Logging</strong>: Ensure comprehensive web server logging is enabled to capture HTTP method, URI stem, and request details for forensic analysis and detection rule activation.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>vulnerability</category><category>web-application</category><category>insecure-configuration</category><category>PraisonAI</category><category>cve</category></item><item><title>Unauthenticated Server-Side Request Forgery in PraisonAI Jobs API (CVE-2026-60091)</title><link>https://feed.craftedsignal.io/briefs/2026-07-praisonai-ssrf/</link><pubDate>Fri, 10 Jul 2026 15:25:05 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-07-praisonai-ssrf/</guid><description>PraisonAI versions before 4.6.78 contain an unauthenticated server-side request forgery (SSRF) vulnerability, CVE-2026-60091, in the Jobs API `/api/v1/runs` endpoint via the `webhook_url` parameter, allowing attackers to exploit DNS rebinding to access internal services.</description><content:encoded><![CDATA[<p>An unauthenticated server-side request forgery (SSRF) vulnerability, identified as CVE-2026-60091, exists in PraisonAI versions prior to 4.6.78. This critical flaw resides within the Jobs API <code>/api/v1/runs</code> endpoint, specifically impacting the <code>webhook_url</code> parameter. Attackers can leverage a timing window where the <code>webhook_url</code> is initially validated as an external, legitimate target but then re-resolved to an internal IP address at connection time using DNS rebinding. This allows an external attacker to bypass security controls and force the PraisonAI application to make blind HTTP requests to arbitrary internal network services, potentially leading to unauthorized information disclosure, interaction with internal systems, or further lateral movement within an organization's network.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li>The attacker registers a domain (e.g., <code>attacker.com</code>) and configures its DNS records with a short Time-To-Live (TTL). Initially, the domain resolves to a legitimate external IP address controlled by the attacker.</li>
<li>The attacker sends an unauthenticated POST request to the PraisonAI Jobs API endpoint <code>/api/v1/runs</code>, setting the <code>webhook_url</code> parameter to their malicious domain (e.g., <code>http://attacker.com/callback</code>).</li>
<li>During initial validation, PraisonAI performs a DNS lookup for <code>attacker.com</code>. At this stage, it resolves to the external IP, passing the validation checks designed to prevent access to internal or private IP ranges.</li>
<li>PraisonAI accepts the job and schedules the webhook callback for later execution.</li>
<li>Before PraisonAI attempts to connect to the <code>webhook_url</code> for the callback, the attacker rapidly updates the DNS record for <code>attacker.com</code> to point to an internal IP address (e.g., <code>192.168.1.10</code>), which hosts an internal service within the target network.</li>
<li>When PraisonAI executes the webhook callback, it performs a new DNS lookup for <code>attacker.com</code>. Due to the DNS rebinding, it now resolves to <code>192.168.1.10</code>.</li>
<li>PraisonAI then makes an HTTP request to <code>http://192.168.1.10/callback</code>, initiating a blind server-side request forgery against an internal service.</li>
<li>The internal service receives the request, potentially allowing the attacker to gather information about the internal network or interact with other internal systems, albeit blindly.</li>
</ol>
<h2 id="impact">Impact</h2>
<p>The successful exploitation of CVE-2026-60091 allows an unauthenticated attacker to bypass network segmentation and access internal services from an external position. This blind SSRF can lead to unauthorized information disclosure (C:L) and potentially limited modification of internal data (I:L), as indicated by its CVSS 3.1 score of 7.2. Attackers can use this vulnerability for internal network reconnaissance, identifying other vulnerable services, or indirectly interacting with sensitive internal systems that are not directly exposed to the internet. While direct arbitrary code execution is not implied, the ability to reach internal resources provides a significant foothold for further attack.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Patch PraisonAI instances immediately to version 4.6.78 or later to address CVE-2026-60091.</li>
<li>Implement strict outbound network filtering on the PraisonAI application server to prevent connections to internal IP ranges (RFC1918 addresses) or other unauthorized destinations. (network_connection logs)</li>
<li>Monitor DNS query logs from the PraisonAI server for suspicious rebinding patterns where a domain initially resolves to an external IP and then quickly changes to an internal IP. (dns_query logs)</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>vulnerability</category><category>ssrf</category><category>dns-rebinding</category><category>praisonai</category></item></channel></rss>