CVE-2026-34936 | MervinPraison PraisonAI up to 4.5.89 passthrough/apassthrough api_base server-side request forgery (GHSA-x6m9-gxvr-7jpv)
A vulnerability was found in MervinPraison PraisonAI up to 4.5.89. It has been rated as critical. This impacts the function passthrough/apassthrough. This manipulation of the argument api_base causes server-side request forgery.
This vulnerability appears as CVE-2026-34936. The attack may be initiated remotely. There is no available exploit.
Upgrading the affected component is advised.