CVE-2026-40160 - PraisonAIAgents has SSRF via unvalidated URL in `web_crawl` httpx fallback
CVE ID :CVE-2026-40160
Published : April 10, 2026, 5:17 p.m. | 49 minutes ago
Description :PraisonAIAgents is a multi-agent teams system. Prior to 1.5.128, web_crawl's httpx fallback path pa...
Related Vulnerabilities
- CVE-2026-40158: PraisonAI is a multi-agent teams system. Prior to 4.5.128, PraisonAI's AST-based Python sandbox can HIGH
- CVE-2026-35643: OpenClaw before 2026.3.22 contains an unvalidated WebView JavascriptInterface vulnerability allowing HIGH
- CVE-2026-40150: PraisonAIAgents is a multi-agent teams system. Prior to 1.5.128, the web_crawl() function in praison HIGH
- CVE-2026-40074: @sveltejs/kit: Unvalidated redirect in handle hook causes Denial-of-Service MEDIUM
- CVE-2026-40160: PraisonAIAgents is a multi-agent teams system. Prior to 1.5.128, web_crawl's httpx fallback path pas HIGH
Related Coverage
Threat Actors