cbcvebase.

Mervinpraison Praisonai vulnerabilities

127 known vulnerabilities affecting mervinpraison/praisonai.

Total CVEs
127
CISA KEV
0
Public exploits
3
Exploited in wild
1
Severity breakdown
CRITICAL40HIGH65MEDIUM22

Vulnerabilities

Page 2 of 7
CVE-2026-40289P2CRITICALCVSS 9.1fixed in 4.6.582026-04-14
CVE-2026-40289 [CRITICAL] CWE-306 CVE-2026-40289: PraisonAI is a multi-agent teams system. In versions below 4.5.139 of PraisonAI and 1.5.140 of prais PraisonAI is a multi-agent teams system. In versions below 4.5.139 of PraisonAI and 1.5.140 of praisonaiagents, the browser bridge (praisonai browser start) is vulnerable to unauthenticated remote session hijacking due to missing authentication and a bypassable origin check on its /ws WebSocket endpoint. The server binds to 0.0.0.0 by default and
ghsanvd
CVE-2026-61426P2HIGHCVSS 8.6fixed in 1.7.32026-07-11
CVE-2026-61426 [HIGH] CWE-200 CVE-2026-61426: PraisonAI before 1.7.3 contains an insecure default configuration that binds to all interfaces with PraisonAI before 1.7.3 contains an insecure default configuration that binds to all interfaces with no API key requirement and wildcard CORS. Unauthenticated attackers can call GET /api/agents to read agent instructions and system prompts, or POST /api/chat to invoke agents without authentication.
nvd
CVE-2026-34937P2CRITICALCVSS 9.8fixed in 1.5.902026-04-03
CVE-2026-34937 [CRITICAL] CWE-78 CVE-2026-34937: PraisonAI is a multi-agent teams system. Prior to version 1.5.90, run_python() in praisonai construc PraisonAI is a multi-agent teams system. Prior to version 1.5.90, run_python() in praisonai constructs a shell command string by interpolating user-controlled code into python3 -c "" and passing it to subprocess.run(..., shell=True). The escaping logic only handles \ and ", leaving $() and backtick substitutions unescaped, allowing arbitrary OS com
nvd
CVE-2026-47392P2CRITICALCVSS 10.0≥ 0, < 4.6.402026-05-29
CVE-2026-47392 [CRITICAL] CWE-184 PraisonAI vulnerable to sandbox escape via `print.__self__` builtins module leak in `execute_code` (subprocess mode) PraisonAI vulnerable to sandbox escape via `print.__self__` builtins module leak in `execute_code` (subprocess mode) ## Summary `execute_code()` in `praisonaiagents/tools/python_tools.py` (v1.6.37, subprocess sandbox mode) can be fully bypassed using `print.__self__` to retrieve the real Python `builtins` module, from which `__import__` can be e
ghsa
CVE-2026-57138P2CRITICALCVSS 9.9v>= 1.4.0, < 1.7.22026-09-15
CVE-2026-57138 [CRITICAL] CWE-184 CVE-2026-57138: PraisonAI is a multi-agent teams system. From 1.4.0 until 1.7.2, codeMode in src/praisonai-ts/src/to PraisonAI is a multi-agent teams system. From 1.4.0 until 1.7.2, codeMode in src/praisonai-ts/src/tools/builtins/code-mode.ts executes untrusted JavaScript with new Function() inside with(sandbox) and relies on a small source-code blocklist plus shadowed process and require properties. Code can use ({}).constructor.constructor to recover the real
nvd
CVE-2026-57141P2CRITICALCVSS 9.8fixed in 1.7.22026-09-15
CVE-2026-57141 [CRITICAL] CWE-94 CVE-2026-57141: PraisonAI is a multi-agent teams system. Prior to 1.7.2, the codeMode tool in src/praisonai-ts/src/t PraisonAI is a multi-agent teams system. Prior to 1.7.2, the codeMode tool in src/praisonai-ts/src/tools/builtins/code-mode.ts executes model-generated JavaScript with new Function() and with(sandbox), while a regular-expression blocklist can be bypassed with Function('return this')() to recover the global object and by constructing the child_proce
nvd
CVE-2026-40151P3MEDIUMCVSS 5.3PoCfixed in 4.5.1282026-04-09
CVE-2026-40151 [MEDIUM] CWE-200 CVE-2026-40151: PraisonAI is a multi-agent teams system. Prior to 4.5.128, the AgentOS deployment platform exposes a PraisonAI is a multi-agent teams system. Prior to 4.5.128, the AgentOS deployment platform exposes a GET /api/agents endpoint that returns agent names, roles, and the first 100 characters of agent system instructions to any unauthenticated caller. The AgentOS FastAPI application has no authentication middleware, no API key validation, and defaults t
ghsanvd
CVE-2026-61434P2HIGHCVSS 8.8fixed in 4.6.782026-07-10
CVE-2026-61434 [HIGH] CWE-78 CVE-2026-61434: PraisonAI versions before 4.6.78 contain an allowlist bypass vulnerability in shell command executio PraisonAI versions before 4.6.78 contain an allowlist bypass vulnerability in shell command execution that allows attackers to execute restricted commands via find's built-in -exec, -execdir, and -delete actions. Attackers can craft find commands with these built-in actions to read blocked files, delete files, or execute non-allowlisted binaries withou
nvd
CVE-2026-34955P2CRITICALCVSS 10.0fixed in 4.5.972026-04-04
CVE-2026-34955 [CRITICAL] CWE-78 CVE-2026-34955: PraisonAI is a multi-agent teams system. Prior to version 4.5.97, SubprocessSandbox in all modes (BA PraisonAI is a multi-agent teams system. Prior to version 4.5.97, SubprocessSandbox in all modes (BASIC, STRICT, NETWORK_ISOLATED) calls subprocess.run() with shell=True and relies solely on string-pattern matching to block dangerous commands. The blocklist does not include sh or bash as standalone executables, allowing trivial sandbox escape in ST
ghsanvdosv
CVE-2026-57133P2HIGHCVSS 8.8v>= 1.5.1, < 1.7.22026-09-15
CVE-2026-57133 [HIGH] CWE-78 CVE-2026-57133: PraisonAI is a multi-agent teams system. From 1.5.1 until 1.7.2, the shell() helper exported from sr PraisonAI is a multi-agent teams system. From 1.5.1 until 1.7.2, the shell() helper exported from src/praisonai-ts/src/tools/utility-tools.ts checks only the first whitespace-delimited token against safeCommands and then passes the complete original string to child_process.exec(). A string that starts with an allowed read-only command can append a seco
nvd
CVE-2026-57136P2HIGHCVSS 8.8v>= 1.2.3, < 1.7.22026-09-15
CVE-2026-57136 [HIGH] CWE-78 CVE-2026-57136: PraisonAI is a multi-agent teams system. From 1.2.3 until 1.7.2, CommandValidator in src/praisonai-t PraisonAI is a multi-agent teams system. From 1.2.3 until 1.7.2, CommandValidator in src/praisonai-ts/src/cli/features/sandbox-executor.ts validates only the first whitespace-delimited executable against allowedCommands, then SandboxExecutor passes the complete command string to sh -c. A command beginning with an allowed executable can append a non-all
nvd
CVE-2026-61435P2HIGHCVSS 8.2fixed in 4.6.782026-07-15
CVE-2026-61435 [HIGH] CWE-287 CVE-2026-61435: PraisonAI before 4.6.78 contains an authentication bypass in the Call API agent invocation endpoints PraisonAI before 4.6.78 contains an authentication bypass in the Call API agent invocation endpoints (src/praisonai/praisonai/api/agent_invoke.py) when PRAISONAI_CALL_AUTH=disabled is configured. The safeguard intended to restrict the disabled-auth opt-out to localhost binding derives the bind host from request.url.hostname, which is taken from the cl
nvd
CVE-2026-34952P3CRITICALCVSS 9.1fixed in 4.5.972026-04-03
CVE-2026-34952 [CRITICAL] CWE-306 CVE-2026-34952: PraisonAI is a multi-agent teams system. Prior to version 4.5.97, the PraisonAI Gateway server accep PraisonAI is a multi-agent teams system. Prior to version 4.5.97, the PraisonAI Gateway server accepts WebSocket connections at /ws and serves agent topology at /info with no authentication. Any network client can connect, enumerate registered agents, and send arbitrary messages to agents and their tool sets. This issue has been patched in version
ghsanvdosv
CVE-2026-40315P3CRITICALCVSS 9.8vpraisonaiagents < 1.6.9vpraisonai < 4.6.92026-04-14
CVE-2026-40315 [CRITICAL] CWE-89 CVE-2026-40315: PraisonAI is a multi-agent teams system. Prior to 4.5.133, there is an SQL identifier injection vuln PraisonAI is a multi-agent teams system. Prior to 4.5.133, there is an SQL identifier injection vulnerability in SQLiteConversationStore where the table_prefix configuration value is directly concatenated into SQL queries via f-strings without any validation or sanitization. Since SQL identifiers cannot be safely parameterized, an attacker who cont
ghsanvd
CVE-2026-57140P2CRITICALCVSS 9.4v>= 1.6.0, < 1.7.22026-09-15
CVE-2026-57140 [CRITICAL] CWE-306 CVE-2026-57140: PraisonAI is a multi-agent teams system. From 1.6.0 until 1.7.2, AgentOS in src/praisonai-ts/src/os/ PraisonAI is a multi-agent teams system. From 1.6.0 until 1.7.2, AgentOS in src/praisonai-ts/src/os/agentos.ts uses the 0.0.0.0 default from src/praisonai-ts/src/os/config.ts and registers GET /api/agents and POST /api/chat without authentication middleware. A remote caller who can reach the service can obtain agent names, roles, and instruction p
nvd
CVE-2026-61436P3HIGHCVSS 8.6fixed in 4.6.782026-07-15
CVE-2026-61436 [HIGH] CWE-287 CVE-2026-61436: PraisonAI before 4.6.78 fails to verify Svix webhook signatures in AgentMail webhook mode, allowing PraisonAI before 4.6.78 fails to verify Svix webhook signatures in AgentMail webhook mode, allowing unauthenticated attackers to forge message.received events. Attackers can send crafted JSON payloads to the webhook endpoint to invoke configured agents with arbitrary sender addresses and message content.
nvd
CVE-2026-55533P3HIGHCVSS 8.2fixed in 4.6.582026-08-25
CVE-2026-55533 [HIGH] CWE-287 CVE-2026-55533: PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.58, create_auth_middleware() allows PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.58, create_auth_middleware() allows requests when auth=api-key lacks PRAISONAI_API_KEY or JWT authentication lacks PRAISONAI_JWT_SECRET. An externally bound Recipe server can therefore accept unauthenticated POST /v1/recipes/run requests despite authentication being enabled. This issue is
ghsanvd
CVE-2026-44336P3CRITICALCVSS 9.6fixed in 4.6.402026-05-08
CVE-2026-44336 [CRITICAL] CWE-20 CVE-2026-44336: PraisonAI is a multi-agent teams system. Prior to version 4.6.34, PraisonAI's MCP (Model Context Pro PraisonAI is a multi-agent teams system. Prior to version 4.6.34, PraisonAI's MCP (Model Context Protocol) server (praisonai mcp serve) registers four file-handling tools by default — praisonai.rules.create, praisonai.rules.show, praisonai.rules.delete, and praisonai.workflow.show. Each accepts a path or filename string from MCP tools/call argument
ghsanvd
CVE-2026-34953P3CRITICALCVSS 9.1fixed in 4.5.972026-04-03
CVE-2026-34953 [CRITICAL] CWE-863 CVE-2026-34953: PraisonAI is a multi-agent teams system. Prior to version 4.5.97, OAuthManager.validate_token() retu PraisonAI is a multi-agent teams system. Prior to version 4.5.97, OAuthManager.validate_token() returns True for any token not found in its internal store, which is empty by default. Any HTTP request to the MCP server with an arbitrary Bearer token is treated as authenticated, granting full access to all registered tools and agent capabilities. Th
ghsanvdosv
CVE-2026-61443P3HIGHCVSS 8.1fixed in 1.6.782026-07-15
CVE-2026-61443 [HIGH] CWE-22 CVE-2026-61443: PraisonAI before 1.6.78 contains a remote code execution vulnerability in SkillTools.run_skill_scrip PraisonAI before 1.6.78 contains a remote code execution vulnerability in SkillTools.run_skill_script() that executes scripts without path containment validation. Attackers can supply absolute file paths to execute arbitrary scripts from any filesystem location, including those outside the intended working directory.
nvd