
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-34954 is a Server-Side Request Forgery (SSRF) vulnerability in the FileTools.download_file() function of the praisonaiagents Python package (part of the PraisonAI framework). The function validates the destination path but passes the url parameter directly to httpx.stream() with follow_redirects=True without any validation, allowing an attacker who controls the URL to reach any host accessible from the server, including cloud metadata services and internal network services. It affects praisonaiagents and praisonai versions up to and including 1.5.94. The vulnerability was published by the maintainer on March 31, 2026, and added to the GitHub Advisory Database on April 1, 2026. It carries a CVSS v3.1 base score of 8.6 (High) (GitHub Advisory, PraisonAI Advisory).
The root cause is CWE-918 (Server-Side Request Forgery), stemming from the absence of URL validation in file_tools.py. The data flow runs from the source at line 259 — where url is accepted directly from the caller with no sanitization — to the sink at line 296, where it is passed to httpx.stream("GET", url, timeout=timeout, follow_redirects=True). The follow_redirects=True flag further enables open-redirect chaining, allowing attackers to bypass any partial URL filters that might exist upstream. The vulnerability is reachable via indirect prompt injection in agentic workflows, requiring no authentication. A public proof-of-concept is available in the security advisory demonstrating exploitation against both a local listener and the AWS EC2 IMDSv1 metadata endpoint (GitHub Advisory, PraisonAI Advisory).
Successful exploitation allows an unauthenticated attacker to make the server issue arbitrary HTTP requests to any host reachable from the server's network context, including loopback addresses, RFC-1918 private networks, and cloud metadata endpoints. On AWS EC2 instances with IMDSv1 enabled, an attacker can retrieve IAM security credentials from http://169.254.169.254/latest/meta-data/iam/security-credentials/ and have them written to a local file for subsequent exfiltration by agent steps. This can lead to full cloud account compromise, lateral movement within internal networks, and exposure of sensitive configuration data — with no impact on integrity or availability, but a critical confidentiality breach (GitHub Advisory, PraisonAI Advisory).
A public proof-of-concept exploit is available in the GitHub Security Advisory, consisting of runnable Python code that calls download_file() with a crafted URL targeting internal services. No authentication is required, and the attack complexity is low. There is no current evidence of in-the-wild exploitation or threat actor attribution. The EPSS score is approximately 0.032% (0.000320), indicating a low but non-zero probability of exploitation in the near term. The vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (GitHub Advisory, Feedly).
praisonaiagents or praisonai version ≤ 1.5.94 that exposes an interface (API, agent workflow, or prompt injection surface) allowing user-controlled input to reach the download_file() function.http://169.254.169.254/latest/meta-data/iam/security-credentials/) or an internal service (e.g., http://10.0.0.1:8080/admin).url parameter to download_file(), either directly via API call or through indirect prompt injection into an agent that uses the FileTools tool. Set PRAISONAI_AUTO_APPROVE=true if needed to bypass approval prompts.destination file on the server's filesystem.169.254.169.254 (AWS IMDSv1), 169.254.170.2 (ECS metadata), or RFC-1918 addresses (10.x.x.x, 172.16.x.x–172.31.x.x, 192.168.x.x) that are not expected in normal operation; unusual outbound connections to internal services on non-standard ports./tmp/ or other writable directories containing cloud credential JSON structures (e.g., files with fields like AccessKeyId, SecretAccessKey, Token); new files in agent working directories with content matching metadata service responses.download_file() calls with URLs targeting loopback (127.0.0.1) or link-local (169.254.x.x) addresses; httpx request logs indicating GET requests to internal IP ranges with follow_redirects=True.praisonaiagents making unexpected network connections observable via netstat or ss to internal or metadata service IPs (GitHub Advisory).Upgrade praisonaiagents and praisonai to version 1.5.95 or later, which contains the fix for this vulnerability. As a network-level workaround, restrict outbound HTTP access from the server hosting PraisonAI to block requests to cloud metadata endpoints (e.g., 169.254.169.254) and internal RFC-1918 address ranges using firewall rules or security groups. Additionally, enforce IMDSv2 (token-required mode) on AWS EC2 instances to prevent unauthenticated metadata access even if SSRF is achieved. The advisory also suggests implementing URL validation in code using an allowlist of permitted schemes and blocking private/loopback IP ranges before passing URLs to httpx.stream() (GitHub Advisory, PraisonAI Advisory).
The vulnerability received coverage from The Hacker Wire and Yazoul.net security advisory blogs shortly after disclosure. A dev.to article titled "7 CVEs in 48 Hours: How PraisonAI Got Completely Owned" highlighted this CVE as part of a broader security audit of the PraisonAI framework, suggesting systemic security issues in the project. Social media discussion was noted on Mastodon and Bluesky, with community members flagging the risk of SSRF in AI agent frameworks as a growing concern. Red Hat also tracked the vulnerability via their CVE database (The Hacker Wire, Red Hat CVE).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."