CPE
high
advisory
Authentication Bypass in PraisonAI Call API via Host Header Spoofing (CVE-2026-61435)
1 rule 2 TTPs 1 CVEPraisonAI versions prior to 4.6.78 contain an authentication bypass vulnerability in the Call API agent invocation endpoints when PRAISONAI_CALL_AUTH=disabled is configured, allowing an unauthenticated attacker to remotely list and invoke registered agents by sending a spoofed 'Host: 127.0.0.1' HTTP header.
PraisonAI
authentication-bypass
vulnerability
web-application
rce-potential
1r
2t
1c
updated
high
advisory
PraisonAI Server-Side Request Forgery via DNS Rebinding and Redirects (CVE-2026-61429)
4 TTPs 1 CVEPraisonAI versions prior to 1.6.78 are vulnerable to server-side request forgery (SSRF) due to an issue in the Crawl4AI/Chromium backend, allowing attackers to bypass existing SSRF validation by employing DNS rebinding and HTTP redirects to access and exfiltrate sensitive internal responses, including canary values.
PoC
PraisonAI
ssrf
vulnerability
dns-rebinding
web-application
4t
1c
updated