LeakyCreds
NewInstant webhook alerts now available — notified within seconds of any credential detection.Learn more →
Home / Vulnerability Intelligence / CVE-2026-34954

CVE-2026-34954 - Vulnerability Analysis

HighCVSS: 8.6

Last Updated: April 3, 2026

PraisonAI - Server Side Request Forgery

Published: April 3, 2026Updated: April 3, 2026Remote Exploitable

Overview

PraisonAI < 1.5.95 contains a server-side request forgery caused by lack of validation on the url parameter in FileTools.download_file(), letting attackers access internal or cloud metadata services, exploit requires attacker-controlled URL.

Severity & Score

Severity: High
CVSS Score: 8.6

Impact

Attackers can access internal network or cloud metadata services, potentially leading to sensitive information disclosure or further network compromise.

Mitigation

Update to version 1.5.95 or later.

Details

CVE ID
CVE-2026-34954
Severity
High
CVSS Score
8.6
Type
server_side_request_forgery
Status
new

CWE

  • CWE-918

CVSS Metrics

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N