Mervinpraison Praisonai vulnerabilities
127 known vulnerabilities affecting mervinpraison/praisonai.
Total CVEs
127
CISA KEV
0
Public exploits
3
Exploited in wild
1
Severity breakdown
CRITICAL40HIGH65MEDIUM22
Vulnerabilities
Page 4 of 7
CVE-2026-61446P3HIGHCVSS 8.4fixed in 1.6.782026-07-15
CVE-2026-61446 [HIGH] CWE-94 CVE-2026-61446: PraisonAI (praisonaiagents) before 1.6.78 contains a remote code execution vulnerability in the plug
PraisonAI (praisonaiagents) before 1.6.78 contains a remote code execution vulnerability in the plugin manager, which loads and executes arbitrary Python (.py) files from project-level and user-home .praisonai/plugins/ directories using importlib spec_from_file_location() and exec_module() without code signing, integrity verification, or sandboxing. An
nvd
CVE-2026-44339P3HIGHCVSS 8.6vpraisonaiagents < 1.6.37vpraisonai < 4.6.372026-05-08
CVE-2026-44339 [HIGH] CWE-470 CVE-2026-44339: PraisonAI is a multi-agent teams system. Prior to praisonai version 4.6.37 and praisonaiagents versi
PraisonAI is a multi-agent teams system. Prior to praisonai version 4.6.37 and praisonaiagents version 1.6.37, praisonaiagents resolves unresolved tool names against module globals and __main__ after it fails to match the declared tool list and the registry. With the default agent configuration, _perm_allow is None, so undeclared non-dangerous tool na
ghsanvd
CVE-2026-57132P3HIGHCVSS 8.2fixed in 4.6.622026-09-14
CVE-2026-57132 [HIGH] CWE-287 CVE-2026-57132: PraisonAI is a multi-agent teams system. Prior to 4.6.62, setting PRAISONAI_CALL_AUTH to disabled ma
PraisonAI is a multi-agent teams system. Prior to 4.6.62, setting PRAISONAI_CALL_AUTH to disabled makes verify_token accept requests to /api/v1/agents/{id}/invoke without CALL_SERVER_TOKEN authentication. Deployments that use the application's advertised opt-out can expose registered agents and their connected tools or private context to unauthenticat
nvd
CVE-2026-40116P3HIGHCVSS 7.5fixed in 4.5.1282026-04-09
CVE-2026-40116 [HIGH] CWE-770 CVE-2026-40116: PraisonAI is a multi-agent teams system. Prior to 4.5.128, the /media-stream WebSocket endpoint in P
PraisonAI is a multi-agent teams system. Prior to 4.5.128, the /media-stream WebSocket endpoint in PraisonAI's call module accepts connections from any client without authentication or Twilio signature validation. Each connection opens an authenticated session to OpenAI's Realtime API using the server's API key. There are no limits on concurrent conne
ghsanvd
CVE-2026-61427P3HIGHCVSS 7.3fixed in 4.6.782026-07-15
CVE-2026-61427 [HIGH] CWE-20 CVE-2026-61427: PraisonAI before 4.6.78 exposes the MCP HTTP-stream transport without authentication by default: the
PraisonAI before 4.6.78 exposes the MCP HTTP-stream transport without authentication by default: the CLI --api-key option defaults to None, and the server only enforces Authorization/Bearer checks when an API key is configured. When an operator runs 'praisonai mcp serve --transport http-stream' without an API key, an unauthenticated client (no Authoriz
nvd
CVE-2026-40154P3CRITICALCVSS 9.6fixed in 4.5.1282026-04-09
CVE-2026-40154 [CRITICAL] CWE-829 CVE-2026-40154: PraisonAI is a multi-agent teams system. Prior to 4.5.128, PraisonAI treats remotely fetched templat
PraisonAI is a multi-agent teams system. Prior to 4.5.128, PraisonAI treats remotely fetched template files as trusted executable code without integrity verification, origin validation, or user confirmation, enabling supply chain attacks through malicious templates. This vulnerability is fixed in 4.5.128.
ghsanvd
CVE-2026-40287P3HIGHCVSS 8.4v>= 4.5.139, < 4.6.322026-04-14
CVE-2026-40287 [HIGH] CWE-94 CVE-2026-40287: PraisonAI is a multi-agent teams system. Versions 4.5.138 and below are vulnerable to arbitrary code
PraisonAI is a multi-agent teams system. Versions 4.5.138 and below are vulnerable to arbitrary code execution through automatic, unsanitized import of a tools.py file from the current working directory. Components including call.py (import_tools_from_file()), tool_resolver.py (_load_local_tools()), and CLI tool-loading paths blindly import ./tools.py
ghsanvd
CVE-2026-55528P3HIGHCVSS 8.2fixed in 4.6.582026-08-25
CVE-2026-55528 [HIGH] CWE-306 CVE-2026-55528: PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.58, AgentServer exposes Server
PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.58, AgentServer exposes ServerConfig.auth_token but AgentServer._create_app does not check it on any route. A remote caller can subscribe, publish, and perform other actions without a valid bearer token or X-Auth-Token even when authentication is configured. This issue is fixed in v
nvd
CVE-2026-57134P3HIGHCVSS 8.2v>= 1.5.1, < 1.7.22026-09-15
CVE-2026-57134 [HIGH] CWE-287 CVE-2026-57134: PraisonAI is a multi-agent teams system. From 1.5.1 until 1.7.2, MCPSecurity.evaluatePolicy() in src
PraisonAI is a multi-agent teams system. From 1.5.1 until 1.7.2, MCPSecurity.evaluatePolicy() in src/praisonai-ts/src/mcp/security.ts invokes the configured credential validator only when AuthMethod is api-key or bearer. Basic and OAuth policies accept any non-empty Authorization header without calling auth.validate(), then return an authenticated res
nvd
CVE-2026-47398P3HIGHCVSS 7.8≥ 0, < 4.6.402026-05-29
CVE-2026-47398 [HIGH] CWE-829 PraisonAI: Arbitrary code execution via unguarded `spec.loader.exec_module` in `agents_generator.py` - sibling of CVE-2026-44334
PraisonAI: Arbitrary code execution via unguarded `spec.loader.exec_module` in `agents_generator.py` - sibling of CVE-2026-44334
Arbitrary code execution via ungated spec.loader.exec_module in agents_generator.py (v4.6.32 chokepoint refactor bypass)
Summary
The v4.6.32 chokepoint refactor (which patched CVE-2026-44334 / GHSA-xcmw-grxf-wjh
ghsa
CVE-2026-57119P3HIGHCVSS 7.5fixed in 4.6.592026-09-14
CVE-2026-57119 [HIGH] CWE-22 CVE-2026-57119: PraisonAI is a multi-agent teams system. Prior to 4.6.59, the unauthenticated Jobs API accepts an ab
PraisonAI is a multi-agent teams system. Prior to 4.6.59, the unauthenticated Jobs API accepts an absolute or traversing agent_file path in POST /api/v1/runs and passes it to the job executor without a workspace allowlist or boundary check. A remote caller can cause the server to open files accessible to the service account, exposing credentials, keys,
nvd
CVE-2026-61428P3HIGHCVSS 7.3fixed in 4.6.782026-07-11
CVE-2026-61428 [HIGH] CWE-290 CVE-2026-61428: PraisonAI AgentMail versions before 4.6.78 lack signature verification in webhook mode, allowing una
PraisonAI AgentMail versions before 4.6.78 lack signature verification in webhook mode, allowing unauthenticated attackers to inject messages with spoofed sender addresses. Attackers can POST crafted message.received events to the webhook endpoint to inject arbitrary content into the agent and trigger replies to attacker-controlled addresses, bypassin
nvd
CVE-2026-57126P3HIGHCVSS 8.5fixed in 1.6.592026-09-14
CVE-2026-57126 [HIGH] CWE-918 CVE-2026-57126: PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.58, SpiderTools._validate_url
PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.58, SpiderTools._validate_url calls _host_is_blocked, which checks literal host encodings but does not resolve DNS names before scrape_page, crawl, extract_links, extract_text, or URL-mention fetches connect. An attacker-controlled hostname resolving to a loopback, private, link-loca
nvd
CVE-2026-40113P3HIGHCVSS 8.1fixed in 4.5.1282026-04-09
CVE-2026-40113 [HIGH] CWE-88 CVE-2026-40113: PraisonAI is a multi-agent teams system. Prior to 4.5.128, deploy.py constructs a single comma-delim
PraisonAI is a multi-agent teams system. Prior to 4.5.128, deploy.py constructs a single comma-delimited string for the gcloud run
deploy --set-env-vars argument by directly interpolating openai_model, openai_key, and openai_base without validating that these values do not contain commas. gcloud uses a comma as the key-value pair separator for --set-en
ghsanvd
CVE-2026-57135P3HIGHCVSS 7.6v>= 1.2.3, < 1.7.22026-09-15
CVE-2026-57135 [HIGH] CWE-653 CVE-2026-57135: PraisonAI is a multi-agent teams system. From 1.2.3 until 1.7.2, SandboxExecutor network-isolated mo
PraisonAI is a multi-agent teams system. From 1.2.3 until 1.7.2, SandboxExecutor network-isolated mode in src/praisonai-ts/src/cli/features/sandbox-executor.ts uses buildEnv() only to inject invalid http_proxy and https_proxy environment variables and does not establish an operating-system network boundary. Programs that ignore those proxy variables c
nvd
CVE-2026-57112P3HIGHCVSS 8.3v>= 3.10.0, < 4.6.592026-09-15
CVE-2026-57112 [HIGH] CWE-306 CVE-2026-57112: PraisonAI is a multi-agent teams system. From praisonaiagents 0.6.0 until 1.6.59 and PraisonAI 3.10.
PraisonAI is a multi-agent teams system. From praisonaiagents 0.6.0 until 1.6.59 and PraisonAI 3.10.0 until 4.6.59, ToolsMCPServer.run_sse() in src/praisonai-agents/praisonaiagents/mcp/mcp_server.py mounts SseServerTransport on the legacy /sse and /messages/ endpoints without default Host, Origin, or authentication enforcement. A malicious website can
nvd
CVE-2026-34936P3HIGHCVSS 7.7fixed in 4.5.902026-04-03
CVE-2026-34936 [HIGH] CWE-918 CVE-2026-34936: PraisonAI is a multi-agent teams system. Prior to version 4.5.90, passthrough() and apassthrough() i
PraisonAI is a multi-agent teams system. Prior to version 4.5.90, passthrough() and apassthrough() in praisonai accept a caller-controlled api_base parameter that is concatenated with endpoint and passed directly to httpx.Client.request() when the litellm primary path raises AttributeError. No URL scheme validation, private IP filtering, or domain all
ghsanvdosv
CVE-2026-35615P3HIGHCVSS 7.5fixed in 4.5.1132026-04-07
CVE-2026-35615 [HIGH] CWE-22 CVE-2026-35615: PraisonAI is a multi-agent teams system. Prior to 1.5.113, _validate_path() calls os.path.normpath()
PraisonAI is a multi-agent teams system. Prior to 1.5.113, _validate_path() calls os.path.normpath() first, which collapses .. sequences, then checks for '..' in normalized. Since .. is already collapsed, the check always passes. This makes the check completely useless and allows trivial path traversal to any file on the system. This vulnerability is f
ghsanvdosv
CVE-2026-44340P3HIGHCVSS 7.5fixed in 4.6.372026-05-08
CVE-2026-44340 [HIGH] CWE-22 CVE-2026-44340: PraisonAI is a multi-agent teams system. Prior to version 4.6.37, the _safe_extractall helper that a
PraisonAI is a multi-agent teams system. Prior to version 4.6.37, the _safe_extractall helper that all recipe pull, recipe publish, and recipe unpack flows route through validates each archive member's name for absolute paths, .. segments, and resolved-path escape — but does not validate member.linkname, does not reject symlink/hardlink members, and ca
ghsanvd
CVE-2026-60085P3HIGHCVSS 7.5fixed in 4.6.782026-07-15
CVE-2026-60085 [HIGH] CWE-273 CVE-2026-60085: PraisonAI before 4.6.78 contains an unenforced security policy vulnerability in the default Subproce
PraisonAI before 4.6.78 contains an unenforced security policy vulnerability in the default Subprocess Sandbox backend where blocked_commands, blocked_paths, blocked_imports, allow_subprocess, and allow_file_write restrictions are completely ignored. Attackers can execute arbitrary subprocess commands, read sensitive files, and perform destructive ope
nvd