Junglewise Threat Intelligence

CVE-2026-57115: PraisonAI SpiderTools redirect validation bypass

CVE-2026-57115 · Severity: medium · CVSS 6.5 · Published 2026-09-14

Technologies: praisonaiagents (PyPI). Vendors: PyPI, MervinPraison.

Executive brief

PraisonAI's SpiderTools component is used to scrape web pages and extract information. A vulnerability allows attackers to redirect users from legitimate URLs to internal services (like metadata endpoints) without proper validation, potentially exposing sensitive internal data that should be blocked from external access.

Technical details

The vulnerability exists in SpiderTools.scrape_page, which validates only the initial URL but allows requests.Session.get to follow HTTP redirects automatically without revalidating the destination. An attacker can craft a public-facing URL that redirects to a private, loopback (127.0.0.1), link-local, or metadata address (e.g., 169.254.169.254). The response body from the redirected private service is then returned through scrape_page and its callers (extract_links, crawl, extract_text), allowing information disclosure from otherwise blocked services. The issue is fixed in praisonaiagents version 1.6.59, which presumably implements proper redirect validation against restricted address ranges.

Affected products

  • MervinPraison PraisonAI prior to 1.6.59

Timeline

  • 2026-09-14: disclosed
  • 2026-06-17: patched: Fixed in praisonaiagents 1.6.59

References

Related threats