CVE-2026-60091 | MervinPraison PraisonAI up to 4.6.77 Jobs API /api/v1/runs webhook_url server-side request forgery
A vulnerability marked as critical has been reported in MervinPraison PraisonAI up to 4.6.77. This impacts an unknown function of the file /api/v1/runs of the component Jobs API. The manipulation of the argument webhook_url leads to server-side request forgery.
This vulnerability is uniquely identified as CVE-2026-60091. The attack is possible to be carried out remotely. No exploit exists.VulDB Recent EntriesRead More