PatchSiren cyber security CVE debrief
CVE-2026-60091 MervinPraison CVE debrief
CVE-2026-60091 is a medium-severity vulnerability in PraisonAI before version 4.6.78, allowing unauthenticated server-side request forgery via the Jobs API /api/v1/runs endpoint. The vulnerability is caused by the webhook_url parameter being validated at request time but re-resolved at connection time, enabling attackers to use DNS rebinding for a blind SSRF attack on internal services.
- Vendor
- MervinPraison
- Product
- PraisonAI
- CVSS
- MEDIUM 6.9
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-08
- Original CVE updated
- 2026-10-08
- Advisory published
- 2026-10-08
- Advisory updated
- 2026-10-08
Who should care
Users of PraisonAI before version 4.6.78 should prioritize updating to the latest version to mitigate this vulnerability. Security teams and administrators responsible for PraisonAI installations should assess their exposure and take necessary actions.
Technical summary
The CVE-2026-60091 vulnerability in PraisonAI before 4.6.78 is caused by improper validation of the webhook_url parameter in the Jobs API /api/v1/runs endpoint. This parameter is validated at request time but re-resolved at connection time, allowing attackers to exploit DNS rebinding and conduct blind SSRF attacks on internal services. The vulnerability has a CVSS score of 6.9 and is classified as medium severity.
Defensive priority
Medium priority should be given to updating PraisonAI to version 4.6.78 or later. Security teams should review their current configurations and assess potential exposure to internal services that could be targeted via this SSRF vulnerability.
Recommended defensive actions
- Update PraisonAI to version 4.6.78 or later
- Review and restrict access to the Jobs API /api/v1/runs endpoint
- Implement additional monitoring for suspicious activity related to SSRF attacks
- Consider implementing compensating controls such as IP blocking or traffic filtering
- Review network configurations to prevent DNS rebinding attacks
- Conduct regular security audits to identify potential vulnerabilities
- Verify that all instances of PraisonAI are running the latest version
Evidence notes
The CVE record was published on 2026-07-10T15:16:49.700Z and last modified on 2026-07-10T17:41:47.303Z. The NVD entry is currently Deferred. Limited details are available about the specific affected configurations and potential attack vectors beyond the provided CVE and NVD information.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-60091 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-60091
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-60091 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-60091
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-4w49-gwv8-fpjg
-
Source reference
Unverified legacy reference
URL: https://www.vulncheck.com/advisories/praisonai-before-unauthenticated-ssrf-via-webhook-url
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.