cbcvebase.

Mervinpraison Praisonai vulnerabilities

127 known vulnerabilities affecting mervinpraison/praisonai.

Total CVEs
127
CISA KEV
0
Public exploits
3
Exploited in wild
1
Severity breakdown
CRITICAL40HIGH65MEDIUM22

Vulnerabilities

Page 3 of 7
CVE-2026-40313P3CRITICALCVSS 9.1fixed in 4.5.1402026-04-14
CVE-2026-40313 [CRITICAL] CWE-829 CVE-2026-40313: PraisonAI is a multi-agent teams system. In versions 4.5.139 and below, the GitHub Actions workflows PraisonAI is a multi-agent teams system. In versions 4.5.139 and below, the GitHub Actions workflows are vulnerable to ArtiPACKED attack, a known credential leakage vector caused by using actions/checkout without setting persist-credentials: false. By default, actions/checkout writes the GITHUB_TOKEN (and sometimes ACTIONS_RUNTIME_TOKEN) into the
nvd
CVE-2026-55539P3HIGHCVSS 8.6fixed in 4.6.582026-08-25
CVE-2026-55539 [HIGH] CWE-306 CVE-2026-55539: PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.51, the Jobs API create_app function PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.51, the Jobs API create_app function mounts /api/v1/runs without authentication. Any reachable caller can submit jobs, read results, cancel runs, or delete jobs using operator credentials. The fix adds PRAISONAI_JOBS_API_KEY middleware for Authorization or X-API-Key. This issue is fixed i
ghsanvd
CVE-2026-34934P3CRITICALCVSS 9.8fixed in 4.5.902026-04-03
CVE-2026-34934 [CRITICAL] CWE-89 CVE-2026-34934: PraisonAI is a multi-agent teams system. Prior to version 4.5.90, the get_all_user_threads function PraisonAI is a multi-agent teams system. Prior to version 4.5.90, the get_all_user_threads function constructs raw SQL queries using f-strings with unescaped thread IDs fetched from the database. An attacker stores a malicious thread ID via update_thread. When the application loads the thread list, the injected payload executes and grants full datab
ghsanvdosv
CVE-2026-44335P3CRITICALCVSS 9.8fixed in 1.6.322026-05-08
CVE-2026-44335 [CRITICAL] CWE-918 CVE-2026-44335: PraisonAI is a multi-agent teams system. Prior to version 1.6.32, the URL checking logic in PraisonA PraisonAI is a multi-agent teams system. Prior to version 1.6.32, the URL checking logic in PraisonAI has a logical flaw that could be bypassed by attackers, leading to SSRF attacks. This issue has been patched in version 1.6.32.
nvd
CVE-2026-40088P3CRITICALCVSS 9.6fixed in 4.5.1212026-04-09
CVE-2026-40088 [CRITICAL] CWE-78 CVE-2026-40088: PraisonAI is a multi-agent teams system. Prior to 4.5.121, the execute_command function and workflow PraisonAI is a multi-agent teams system. Prior to 4.5.121, the execute_command function and workflow shell execution are exposed to user-controlled input via agent workflows, YAML definitions, and LLM-generated tool calls, allowing attackers to inject arbitrary shell commands through shell metacharacters. This vulnerability is fixed in 4.5.121.
ghsanvdosv
CVE-2026-57122P3HIGHCVSS 8.6fixed in 4.6.592026-09-14
CVE-2026-57122 [HIGH] CWE-345 CVE-2026-57122: PraisonAI is a multi-agent teams system. Prior to 4.6.59, the WhatsApp and Linear bot webhook handle PraisonAI is a multi-agent teams system. Prior to 4.6.59, the WhatsApp and Linear bot webhook handlers verify HMAC signatures only when WHATSAPP_APP_SECRET or LINEAR_WEBHOOK_SECRET is configured and otherwise parse and dispatch unsigned request bodies. A remote unauthenticated client that reaches the webhook route can forge messages, comments, or agen
nvd
CVE-2026-60090P3CRITICALCVSS 9.8fixed in 4.6.782026-07-11
CVE-2026-60090 [CRITICAL] CWE-89 CVE-2026-60090: PraisonAI before 4.6.78 fails to validate the caller-controlled dimension argument in the PGVector a PraisonAI before 4.6.78 fails to validate the caller-controlled dimension argument in the PGVector and Cassandra knowledge-store create_collection() backends. Although schema, keyspace, and collection-name identifiers are validated, the dimension value (declared as int but not enforced at runtime) is interpolated directly into the vector column of
nvd
CVE-2026-47394P3CRITICALCVSS 9.4≥ 0, < 4.6.402026-05-29
CVE-2026-47394 [CRITICAL] CWE-200 PraisonAI vulnerable to unauthenticated arbitrary file read via MCP workflow.show, workflow.validate, deploy.validate PraisonAI vulnerable to unauthenticated arbitrary file read via MCP workflow.show, workflow.validate, deploy.validate ## Summary The fix for GHSA-9mqq-jqxf-grvw / CVE-2026-44336 is incomplete. The original advisory description named four vulnerable handlers in `mcp_server/adapters/cli_tools.py`: > "registers four file-handling tools by default
ghsa
CVE-2026-61444P3CRITICALCVSS 9.1fixed in 4.6.782026-07-10
CVE-2026-61444 [CRITICAL] CWE-94 CVE-2026-61444: PraisonAI versions before 4.6.78 contain a code injection vulnerability in deploy/api.py where the a PraisonAI versions before 4.6.78 contain a code injection vulnerability in deploy/api.py where the agents_file parameter is directly interpolated into an f-string without sanitization. Attackers can inject arbitrary Python code that executes when the generated server code runs via subprocess.Popen().
nvd
CVE-2026-57137P3HIGHCVSS 8.8v>= 1.4.0, < 1.7.22026-09-15
CVE-2026-57137 [HIGH] CWE-693 CVE-2026-57137: PraisonAI is a multi-agent teams system. From 1.4.0 until 1.7.2, createAgentLoop() in src/praisonai- PraisonAI is a multi-agent teams system. From 1.4.0 until 1.7.2, createAgentLoop() in src/praisonai-ts/src/ai/agent-loop.ts passes executable tools to generateText() before invoking the onToolCall approval callback. Because the wrapped AI SDK executes tool handlers during generation, a callback that returns false records tool_rejected only after the d
nvd
CVE-2026-55541P3HIGHCVSS 8.8fixed in 4.6.582026-08-25
CVE-2026-55541 [HIGH] CWE-862 CVE-2026-55541: PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.58, praisonai serve agents and prais PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.58, praisonai serve agents and praisonai serve unified parse --api-key but _create_agents_app() and _create_unified_app() do not install a credential check. Unauthenticated callers can reach POST /agents and POST /api/v1/agents/{id}/invoke. This issue is fixed in version 4.6.58.
ghsanvd
CVE-2026-55534P3HIGHCVSS 8.6v>= 4.6.34, < 4.6.582026-08-25
CVE-2026-55534 [HIGH] CWE-306 CVE-2026-55534: PraisonAI is a multi-agent teams system. From praisonai 4.6.34 until 4.6.58, praisonai serve agents PraisonAI is a multi-agent teams system. From praisonai 4.6.34 until 4.6.58, praisonai serve agents accepts --api-key but _create_agents_app() does not authenticate POST /agents or POST /agents/{agent_name}. A network caller can invoke configured agents without credentials even when an API key was supplied. This issue is fixed in version 4.6.58.
ghsanvd
CVE-2026-34954P3HIGHCVSS 8.6fixed in 1.5.952026-04-03
CVE-2026-34954 [HIGH] CWE-918 CVE-2026-34954: PraisonAI is a multi-agent teams system. Prior to version 1.5.95, FileTools.download_file() in prais PraisonAI is a multi-agent teams system. Prior to version 1.5.95, FileTools.download_file() in praisonaiagents validates the destination path but performs no validation on the url parameter, passing it directly to httpx.stream() with follow_redirects=True. An attacker who controls the URL can reach any host accessible from the server including cloud m
nvd
CVE-2026-61430P3HIGHCVSS 8.5fixed in 1.6.782026-07-15
CVE-2026-61430 [HIGH] CWE-918 CVE-2026-61430: PraisonAI before 1.6.78 contains a server-side request forgery vulnerability in the web_crawl tool t PraisonAI before 1.6.78 contains a server-side request forgery vulnerability in the web_crawl tool that validates hostnames at check time but re-resolves them at connection time without IP pinning. Attackers can use DNS rebinding to bypass SSRF protection and retrieve internal HTTP response bodies from private or loopback services.
nvd
CVE-2026-57145P3CRITICALCVSS 9.1fixed in 4.6.622026-09-14
CVE-2026-57145 [CRITICAL] CWE-22 CVE-2026-57145: PraisonAI is a multi-agent teams system. Prior to 4.6.62, src/praisonai/praisonai/tools/multiedit.py PraisonAI is a multi-agent teams system. Prior to 4.6.62, src/praisonai/praisonai/tools/multiedit.py passes the LLM-controlled filepath parameter directly to open for reading and writing without traversal rejection, symlink resolution, a workspace boundary, or protected-path checks. Prompt-influenced agents can read files through edit and diff beha
nvd
CVE-2026-55536P3CRITICALCVSS 9.1≥ 0, < 4.6.582026-08-25
CVE-2026-55536 [CRITICAL] CWE-284 PraisonAI has a Browser Server WebSocket origin validation bypass via unanchored regex (patch bypass of CVE-2026-40289 / GHSA-8x8f-54wf-vv92) PraisonAI has a Browser Server WebSocket origin validation bypass via unanchored regex (patch bypass of CVE-2026-40289 / GHSA-8x8f-54wf-vv92) ### Summary `praisonai/browser/server.py` validates incoming WebSocket connections using a Chrome extension Origin check. The regex `chrome-extension://[a-z0-9]{32}` is applied wit
ghsa
CVE-2026-39891P3HIGHCVSS 8.8fixed in 4.5.1152026-04-08
CVE-2026-39891 [HIGH] CWE-94 CVE-2026-39891: PraisonAI is a multi-agent teams system. Prior to 4.5.115, the create_agent_centric_tools() function PraisonAI is a multi-agent teams system. Prior to 4.5.115, the create_agent_centric_tools() function returns tools (like acp_create_file) that process file content using template rendering. When user input from agent.start() is passed directly into these tools without escaping, template expressions in the input are executed rather than treated as liter
ghsanvdosv
CVE-2026-40157P3HIGHCVSS 8.8fixed in 4.5.1282026-04-10
CVE-2026-40157 [HIGH] CWE-22 CVE-2026-40157: PraisonAI is a multi-agent teams system. Prior to 4.5.128, cmd_unpack in the recipe CLI extracts .pr PraisonAI is a multi-agent teams system. Prior to 4.5.128, cmd_unpack in the recipe CLI extracts .praison tar archives using raw tar.extract() without validating archive member paths. A .praison bundle containing ../../ entries will write files outside the intended output directory. An attacker who distributes a malicious bundle can overwrite arbitrary
ghsanvd
CVE-2026-61429P3HIGHCVSS 8.5fixed in 1.6.782026-07-11
CVE-2026-61429 [HIGH] CWE-918 CVE-2026-61429: PraisonAI versions before 1.6.78 contain a server-side request forgery vulnerability in the Crawl4AI PraisonAI versions before 1.6.78 contain a server-side request forgery vulnerability in the Crawl4AI/Chromium backend that allows attackers to bypass SSRF validation by exploiting DNS rebinding and HTTP redirects. Attackers can craft URLs that resolve to internal services after the initial validation check, enabling the headless browser to follow redi
nvd
CVE-2026-55526P3HIGHCVSS 8.5fixed in 4.6.582026-08-25
CVE-2026-55526 [HIGH] CWE-350 CVE-2026-55526: PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.58, spider_tools._host_is_bloc PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.58, spider_tools._host_is_blocked() does not resolve ordinary hostnames before scrape_page fetches them. A hostname such as 127.0.0.1.nip.io passes validation and resolves to loopback, permitting internal HTTP access. The fix uses socket.getaddrinfo and fails closed on DNS errors. T
nvd
Mervinpraison Praisonai vulnerabilities | cvebase