Sploitus

CVE-2026-61429

No indexed exploits for CVE-2026-61429 yet

PraisonAI versions before 1.6.78 contain a server-side request forgery vulnerability in the Crawl4AI/Chromium backend that allows attackers to bypass SSRF validation by exploiting DNS rebinding and HTTP redirects. Attackers can craft URLs that resolve to internal services after the initial validation check, enabling the headless browser to follow redirects and read internal responses including sensitive canary values.

Affected products
Chromium, Crawl4Ai, Praisonai
Fix
Available
CVSS 3.1
8.5 HIGH
EPSS
0.2% (13th percentile)
Weakness
CWE-918
NVD status
Deferred
Published
2026-07-11
CVE-2026-61429 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2026-61429 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2026-61429 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.