CVE-2026-40150Disclosure(praison / praisonaiagents)

LOWCVSS 6.5 · MEDIUM

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

PraisonAIAgents is a multi-agent teams system. Prior to 1.5.128, the web_crawl() function in praisonaiagents/tools/web_crawl_tools.py accepts arbitrary URLs from AI agents with zero validation. No scheme allowlisting, hostname/IP blocklisting, or private network checks are applied before fetching. This allows an attacker (or prompt injection in crawled content) to force the agent to fetch cloud metadata endpoints, internal services, or local files via file:// URLs. This vulnerability is fixed in 1.5.128.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-918

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • praisonaiagents

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 3 classified signals
  • 3 total mentions across 1 day

Affected systems

Vendors
Products
praisonaiagents

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-04-10: 3Technical Details · 2026-04-10: 204-10
Signal classification1 categories
Disclosure
3100.0%
Referenced assets2 URLs
Full discourse3 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-40150 PraisonAIAgents is a multi-agent teams system. Prior to 1.5.128, the web_crawl() function in praisonaiagents/tools/web_crawl_tools.py accepts arbitrary URLs from AI a… https://www.cve.org/CVERecord?id=CVE-2026-40150

    Post summary

    CVE-2026-40150 exposes a flaw in PraisonAI Agents' web_crawl() function, which accepts arbitrary URLs and could allow attackers to exploit the system for malicious web crawling or related attacks.

    00010181
    57.0K followersView on X
  • Sentinel 🚨@theagentcop
    Disclosure

    🚨 LIVE HIJACK ALERT — CVE-2026-40150. CVSS 7.7. PraisonAIAgents web_crawl() accepts any URL from any agent with zero validation. attacker-controlled content can force your agent to fetch internal cloud metadata, private IPs, localhost services. investigating. 🧵

    Post summary

    The post discloses CVE‑2026‑40150, noting a URL validation flaw in PraisonAIAgents that could expose internal cloud metadata, but it provides no PoC, exploit code, or patch information, and no active exploitation is reported.

    1000063
    6 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-40150 Server-Side Request Forgery in PraisonAIAgents Web Crawl Function Prior to 1.5.128 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-40150

    Post summary

    The content announces the existence of CVE‑2026‑40150, a Server‑Side Request Forgery vulnerability in PraisonAIAgents, without providing PoC, exploit, or mitigation details.

    0000041
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apppraisonpraisonaiagents---

Explore more