Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-40114

35
FAUCET Score

CVE-2026-40114 is a server-side request forgery (SSRF) vulnerability in PraisonAI versions prior to 4.5.128 that affects the /api/v1/runs endpoint. The flaw stems from a lack of URL validation on the webhook_url parameter, allowing unauthenticated attackers to inject arbitrary webhook URLs that the server will POST to upon job completion. This enables attackers to redirect requests toward cloud metadata services, internal APIs, and other network-adjacent resources. The vulnerability carries a CVSS score of 10.0 (Critical) with a network-based attack vector requiring no authentication, privileges, or user interaction. The attack has low complexity and can result in compromised confidentiality and integrity across the system boundary. The FAUCET risk score of 56.0 indicates moderate organizational risk, though the EPSS value of 0.00043 suggests relatively low probability of exploitation in the wild at this time. While not yet documented on the Known Exploited Vulnerabilities (KEV) catalog, the vulnerability appears on active monitoring lists, warranting immediate attention. Organizations running PraisonAI should upgrade to version 4.5.128 or later without delay to remediate this critical SSRF exposure, particularly those with sensitive internal systems accessible from the affected server's network segment.

Impacted Technologies

VendorProductVersion(s)CPE
< 4.5.128CPE matchmatch criteria
cpe:2.3:a:praison:praisonai:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.2HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
CHANGED
Confidentiality Impact
LOW
Integrity Impact
LOW
Availability Impact
NONE
Exploitability Score
3.9
Impact Score
2.7
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.28%
Probability of exploitation in next 30 days
EPSS Percentile
20.3%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0028 is in the 2nd percentile among its peer group of 36,897 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (1)

pippatch availablevia ghsa
Product: PraisonAIFixed in: 4.5.128

Vendor Advisories (1)

pipGHSA-8frj-8q3m-xhgmhigh

PraisonAI Vulnerable to Server-Side Request Forgery via Unvalidated webhook_url in Jobs API

Apr 10, 2026

References

github.com / MervinPraison/PraisonAI/security/advisories/GHSA-8frj-8q3m-xhgm
ExploitVendor Advisory