Junglewise Threat Intelligence

PraisonAI SpiderTools SSRF protection bypass via redirects

Severity: medium · CVSS 6.5 · Published 2026-06-18

Vendors: PraisonAI.

Executive brief

PraisonAI's SpiderTools, a component used for web scraping and crawling, contains a security flaw that allows it to access internal network resources it is supposed to block. While the tool checks the initial web address provided, it fails to check subsequent addresses if that initial site redirects the request elsewhere. This could allow an attacker to trick the system into reading sensitive data from internal services, local files, or cloud metadata endpoints that are not intended to be public.

Technical details

A Server-Side Request Forgery (SSRF) vulnerability exists in the `SpiderTools.scrape_page()` method and its callers (`extract_links`, `crawl`, `extract_text`). While the component implements a `_validate_url()` check to block loopback, private, and metadata IP addresses, it uses the Python `requests` library with default settings that automatically follow HTTP 3xx redirects. An attacker can provide a URL to a malicious server that passes the initial validation but then issues a redirect to a restricted internal target (e.g., 127.0.0.1 or 169.254.169.254). Because the redirect target is not re-validated, the tool will fetch and return the content from the restricted resource. The vulnerability is addressed in version 1.6.59 by ensuring redirect targets are validated or redirects are disabled.

Affected products

  • PraisonAI praisonaiagents <= 1.6.58

Timeline

  • 2026-06-17: disclosed
  • 2026-06-18: advisory: GHSA-6h9p-93hq-q7h6 published
  • 2026-06-18: patched: Fixed in version 1.6.59

References