CVE-2026-34954
HIGH SEVERITYCVSS Score & Metrics
Base Score
8.6 / 10
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
Vulnerability Description
PraisonAI is a multi-agent teams system. Prior to version 1.5.95, FileTools.download_file() in praisonaiagents validates the destination path but performs no validation on the url parameter, passing it directly to httpx.stream() with follow_redirects=True. An attacker who controls the URL can reach any host accessible from the server including cloud metadata services and internal network services. This issue has been patched in version 1.5.95.
Vulnerability Details
Published Date
Last Modified
CWE ID
CWE-918
Source
GitHub
Vendor
pip
Product
praisonaiagents
Discussion (0)
Add Comment
No comments yet. Be the first!