cbcvebase.

Mervinpraison Praisonai vulnerabilities

127 known vulnerabilities affecting mervinpraison/praisonai.

Total CVEs
127
CISA KEV
0
Public exploits
3
Exploited in wild
1
Severity breakdown
CRITICAL40HIGH65MEDIUM22

Vulnerabilities

Page 1 of 7
CVE-2026-44338P2HIGHCVSS 7.3ExploitedPoCfixed in 4.6.402026-05-08
CVE-2026-44338 [HIGH] CWE-306 CVE-2026-44338: PraisonAI is a multi-agent teams system. From version 2.5.6 to before version 4.6.34, PraisonAI ship PraisonAI is a multi-agent teams system. From version 2.5.6 to before version 4.6.34, PraisonAI ships a legacy Flask API server with authentication disabled by default. When that server is used, any caller that can reach it can access /agents and trigger the configured agents.yaml workflow through /chat without providing a token. This issue has been p
ghsanvd
CVE-2026-61447P2CRITICALCVSS 10.0PoCfixed in 1.6.782026-07-11
CVE-2026-61447 [CRITICAL] CWE-94 CVE-2026-61447: PraisonAI before 1.6.78 contains a remote code execution vulnerability in CodeAgent._execute_python( PraisonAI before 1.6.78 contains a remote code execution vulnerability in CodeAgent._execute_python() that executes LLM-generated Python code without AST validation, import restrictions, or sandbox enforcement. Attackers can influence LLM output through prompt injection to exfiltrate all environment secrets and execute arbitrary code on the host sy
nvd
CVE-2026-47391P2CRITICALCVSS 9.8fixed in 4.6.402026-07-21
CVE-2026-47391 [CRITICAL] CWE-95 CVE-2026-47391: PraisonAI is a multi-agent teams system. Prior to version 4.6.40, PraisonAI's first-party A2A server PraisonAI is a multi-agent teams system. Prior to version 4.6.40, PraisonAI's first-party A2A server example exposes an unauthenticated A2A JSON-RPC endpoint and registers a `calculate(expression)` tool implemented with Python `eval()`. The example also binds to `0.0.0.0`. A remote unauthenticated attacker can send `message/send` to `/a2a`; the req
ghsanvd
CVE-2026-40114P2CRITICALCVSS 10.0fixed in 4.6.582026-04-09
CVE-2026-40114 [CRITICAL] CWE-918 CVE-2026-40114: PraisonAI is a multi-agent teams system. Prior to 4.5.128, the /api/v1/runs endpoint accepts an arbi PraisonAI is a multi-agent teams system. Prior to 4.5.128, the /api/v1/runs endpoint accepts an arbitrary webhook_url in the request body with no URL validation. When a submitted job completes (success or failure), the server makes an HTTP POST request to this URL using httpx.AsyncClient. An unauthenticated attacker can use this to make the server
ghsanvd
CVE-2026-57124P2CRITICALCVSS 9.8fixed in 4.6.592026-09-14
CVE-2026-57124 [CRITICAL] CWE-78 CVE-2026-57124: PraisonAI is a multi-agent teams system. Prior to 4.6.59, the default UI host applications expose PO PraisonAI is a multi-agent teams system. Prior to 4.6.59, the default UI host applications expose POST /api/mcp/connect without mandatory authentication and accept caller-controlled command and args values that PraisonAIUI passes to StdioMCPClient to start a local process. Because the UI commands bind to 0.0.0.0 by default, a reachable unauthentica
nvd
CVE-2026-57147P2CRITICALCVSS 9.8fixed in 4.6.512026-09-15
CVE-2026-57147 [CRITICAL] CWE-798 CVE-2026-57147: PraisonAI is a multi-agent teams system. Prior to 0.1.6, praisonai_platform/services/auth_service.py PraisonAI is a multi-agent teams system. Prior to 0.1.6, praisonai_platform/services/auth_service.py assigns the public dev-secret-change-me value to JWT_SECRET when PLATFORM_JWT_SECRET is unset, and its production guard does not run when PLATFORM_ENV is also unset because that setting defaults to dev. A remote unauthenticated attacker can mint an
nvd
CVE-2026-47396P2CRITICALCVSS 9.8fixed in 4.6.402026-07-21
CVE-2026-47396 [CRITICAL] CWE-284 CVE-2026-47396: PraisonAI is a multi-agent teams system. Prior to version 4.6.40, PraisonAI's call server exposes a PraisonAI is a multi-agent teams system. Prior to version 4.6.40, PraisonAI's call server exposes a network-facing agent control API without authentication when `CALL_SERVER_TOKEN` is not configured. The affected component is the `praisonai.api.agent_invoke` router as mounted by `praisonai.api.call`. The authentication helper `verify_token()` fails
ghsanvd
CVE-2026-57125P2CRITICALCVSS 9.8fixed in 4.6.592026-09-14
CVE-2026-57125 [CRITICAL] CWE-306 CVE-2026-57125: PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.59 and praisonaiagents 1.6.59, the u PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.59 and praisonaiagents 1.6.59, the unauthenticated POST /api/v1/runs Jobs API accepts attacker-controlled agent_yaml, and the approve field can mark execute_command as YAML-approved before @require_approval checks critical tools. This chain allows a remote caller to cause a configured
nvd
CVE-2026-48168P2CRITICALCVSS 10.0fixed in 4.6.402026-08-05
CVE-2026-48168 [CRITICAL] CWE-862 CVE-2026-48168: PraisonAI is a multi-agent teams system. In versions prior to 4.6.40, the bundled Claude GitHub Acti PraisonAI is a multi-agent teams system. In versions prior to 4.6.40, the bundled Claude GitHub Actions workflow is vulnerable to command injection because it embeds an attacker-controlled pull request branch name into a Bash run: block without quoting or validation. Additionally, the workflow allows any @claude comment to trigger the job regardle
nvd
CVE-2026-61445P2CRITICALCVSS 9.9fixed in 4.6.782026-07-11
CVE-2026-61445 [CRITICAL] CWE-22 CVE-2026-61445: PraisonAI before 4.6.78 contains arbitrary file write and command execution vulnerabilities in the A PraisonAI before 4.6.78 contains arbitrary file write and command execution vulnerabilities in the AICoder component due to missing path validation and command sanitization in LLM tool calls. Attackers can inject malicious prompts through the chat interface to write files to arbitrary filesystem locations and execute arbitrary shell commands with r
nvd
CVE-2026-40288P2CRITICALCVSS 9.8fixed in 4.5.1392026-04-14
CVE-2026-40288 [CRITICAL] CWE-78 CVE-2026-40288: PraisonAI is a multi-agent teams system. In versions below 4.5.139 of PraisonAI and 1.5.140 of prais PraisonAI is a multi-agent teams system. In versions below 4.5.139 of PraisonAI and 1.5.140 of praisonaiagents, the workflow engine is vulnerable to arbitrary command and code execution through untrusted YAML files. When praisonai workflow run loads a YAML file with type: job, the JobWorkflowExecutor in job_workflow.py processes steps that support
ghsanvd
CVE-2026-57127P2CRITICALCVSS 9.8fixed in 4.6.482026-09-14
CVE-2026-57127 [CRITICAL] CWE-306 CVE-2026-57127: PraisonAI is a multi-agent teams system. Prior to 4.6.58, recipe serve installs APIKeyAuthMiddleware PraisonAI is a multi-agent teams system. Prior to 4.6.58, recipe serve installs APIKeyAuthMiddleware or JWTAuthMiddleware when an operator selects api-key or JWT authentication, but each middleware forwards requests when PRAISONAI_API_KEY or PRAISONAI_JWT_SECRET and the corresponding recipe value are absent. Unauthenticated clients can then reach
nvd
CVE-2026-34938P2CRITICALCVSS 10.0fixed in 4.6.402026-04-03
CVE-2026-34938 [CRITICAL] CWE-693 CVE-2026-34938: PraisonAI is a multi-agent teams system. Prior to version 1.5.90, execute_code() in praisonai-agents PraisonAI is a multi-agent teams system. Prior to version 1.5.90, execute_code() in praisonai-agents runs attacker-controlled Python inside a three-layer sandbox that can be fully bypassed by passing a str subclass with an overridden startswith() method to the _safe_getattr wrapper, achieving arbitrary OS command execution on the host. This issue
nvd
CVE-2026-57131P2CRITICALCVSS 9.8fixed in 4.6.482026-09-14
CVE-2026-57131 [CRITICAL] CWE-94 CVE-2026-57131: PraisonAI is a multi-agent teams system. Prior to 4.6.58, praisonai.jobs.server.create_app mounts pr PraisonAI is a multi-agent teams system. Prior to 4.6.58, praisonai.jobs.server.create_app mounts praisonai.jobs.router.create_router under /api/v1/runs without authentication or per-job authorization. Network clients can submit attacker-controlled prompts and agent configuration, list and read jobs, stream results, and cancel or delete other jobs,
nvd
CVE-2026-39890P2CRITICALCVSS 9.8fixed in 4.5.1152026-04-08
CVE-2026-39890 [CRITICAL] CWE-502 CVE-2026-39890: PraisonAI is a multi-agent teams system. Prior to 4.5.115, the AgentService.loadAgentFromFile method PraisonAI is a multi-agent teams system. Prior to 4.5.115, the AgentService.loadAgentFromFile method uses the js-yaml library to parse YAML files without disabling dangerous tags (such as !!js/function and !!js/undefined). This allows an attacker to craft a malicious YAML file that, when parsed, executes arbitrary JavaScript code. An attacker can
ghsanvdosv
CVE-2026-47393P2HIGHCVSS 7.3≥ 0, < 4.6.402026-05-29
CVE-2026-47393 [HIGH] CWE-1188 PraisonAI `deploy --type api` emits a Flask server with authentication disabled by default PraisonAI `deploy --type api` emits a Flask server with authentication disabled by default ### Summary CVE-2026-44338 (GHSA-6rmh-7xcm-cpxj) documents that PraisonAI ships a code-generator (`praisonai.deploy.api.generate_api_server_code`) that emits a Flask API server with authentication disabled by default. Users who follow the documented quickstart (`praisonai deploy --typ
ghsa
CVE-2026-34935P2CRITICALCVSS 9.8fixed in 4.6.92026-04-03
CVE-2026-34935 [CRITICAL] CWE-78 CVE-2026-34935: PraisonAI is a multi-agent teams system. From version 4.5.15 to before version 4.5.69, the --mcp CLI PraisonAI is a multi-agent teams system. From version 4.5.15 to before version 4.5.69, the --mcp CLI argument is passed directly to shlex.split() and forwarded through the call chain to anyio.open_process() with no validation, allowlist check, or sanitization at any hop, allowing arbitrary OS command execution as the process user. This issue has be
ghsanvdosv
CVE-2026-39305P2CRITICALCVSS 10.0fixed in 4.5.1132026-04-07
CVE-2026-39305 [CRITICAL] CWE-22 CVE-2026-39305: PraisonAI is a multi-agent teams system. Prior to 1.5.113, the Action Orchestrator feature contains PraisonAI is a multi-agent teams system. Prior to 1.5.113, the Action Orchestrator feature contains a Path Traversal vulnerability that allows an attacker (or compromised agent) to write to arbitrary files outside of the configured workspace directory. By supplying relative path segments (../) in the target path, malicious actions can overwrite sens
ghsanvdosv
CVE-2026-57139P2CRITICALCVSS 9.8v>= 1.5.0, < 1.7.22026-09-15
CVE-2026-57139 [CRITICAL] CWE-306 CVE-2026-57139: PraisonAI is a multi-agent teams system. From 1.5.0 until 1.7.2, MCPServer.startHttp() in src/praiso PraisonAI is a multi-agent teams system. From 1.5.0 until 1.7.2, MCPServer.startHttp() in src/praisonai-ts/src/mcp/server.ts binds without a host restriction and forwards every HTTP POST request to handleRequest() without authentication or authorization. Any network client that can reach the port can call tools/list, tools/call, resources/read, or
nvd
CVE-2026-57148P2CRITICALCVSS 9.8fixed in 4.6.512026-09-15
CVE-2026-57148 [CRITICAL] CWE-287 CVE-2026-57148: PraisonAI is a multi-agent teams system. Prior to 0.1.6, praisonai_platform/services/auth_service.py PraisonAI is a multi-agent teams system. Prior to 0.1.6, praisonai_platform/services/auth_service.py falls back to the public dev-secret-change-me HS256 signing key when PLATFORM_JWT_SECRET is unset, while the startup and token-issuance guards are disabled because PLATFORM_ENV also defaults to dev. An unauthenticated attacker can sign a JWT contai
nvd