This vulnerability is trending on Twitter; this may indicate a growing threat.
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsLearn about Server-side Request Forgery (SSRF) vulnerabilities in an interactive lesson.
Start learningUpgrade praisonaiagents to version 1.6.62 or higher.
praisonaiagents is a Praison AI agents for completing complex tasks with Self Reflection Agents
Affected versions of this package are vulnerable to Server-side Request Forgery (SSRF) via the searxng_url parameter in the search_web and searxng_search functions. An attacker can cause the server to make arbitrary HTTP requests to internal or external endpoints and retrieve sensitive information by supplying a crafted URL, potentially exposing internal services, APIs, or cloud metadata. This is only exploitable if an agent ingests attacker-controlled content, such as web pages, files, or tool output, which can trigger the vulnerable function through prompt injection.