CVE-2026-40114 is a server-side request forgery (SSRF) vulnerability in PraisonAI versions prior to 4.5.128 that affects the /api/v1/runs endpoint. The flaw stems from a lack of URL validation on the webhook_url parameter, allowing unauthenticated attackers to inject arbitrary webhook URLs that the server will POST to upon job completion. This enables attackers to redirect requests toward cloud metadata services, internal APIs, and other network-adjacent resources. The vulnerability carries a CVSS score of 10.0 (Critical) with a network-based attack vector requiring no authentication, privileges, or user interaction. The attack has low complexity and can result in compromised confidentiality and integrity across the system boundary. The FAUCET risk score of 56.0 indicates moderate organizational risk, though the EPSS value of 0.00043 suggests relatively low probability of exploitation in the wild at this time. While not yet documented on the Known Exploited Vulnerabilities (KEV) catalog, the vulnerability appears on active monitoring lists, warranting immediate attention. Organizations running PraisonAI should upgrade to version 4.5.128 or later without delay to remediate this critical SSRF exposure, particularly those with sensitive internal systems accessible from the affected server's network segment.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 4.5.128CPE matchmatch criteria | cpe:2.3:a:praison:praisonai:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.