Junglewise Threat Intelligence

PraisonAI SSRF in SearxNG and search_web tools

Severity: high · CVSS 8.8 · Published 2026-06-18

Technologies: MervinPraison PraisonAI Agents. Vendors: MervinPraison.

Executive brief

PraisonAI, a framework for building AI agents, contains a vulnerability in its web search tools. An attacker can use malicious content to trick an AI agent into making requests to internal company servers or cloud metadata services. This could allow the attacker to steal sensitive internal data, scan private networks, or potentially access cloud credentials, leading to a significant data breach.

Technical details

A Server-Side Request Forgery (SSRF) exists in the `searxng_search` and `search_web` tools of PraisonAI due to a lack of validation on the `searxng_url` parameter. This parameter is passed directly to the `requests.get()` function without checking the scheme, host, or port. Because this parameter is exposed to the LLM as a tool argument, an attacker can use prompt injection via untrusted content (like a website the agent is browsing) to coerce the agent into requesting internal resources. This can be used to access internal APIs, perform port scanning, or reach cloud instance metadata endpoints (169.254.169.254). The vulnerability is patched in version 1.6.61.

Affected products

  • MervinPraison praisonaiagents < 1.6.61

Timeline

  • 2026-06-17: disclosed
  • 2026-06-18: advisory

References

Related threats