cbcvebase.

Mervinpraison Praisonai vulnerabilities

127 known vulnerabilities affecting mervinpraison/praisonai.

Total CVEs
127
CISA KEV
0
Public exploits
3
Exploited in wild
1
Severity breakdown
CRITICAL40HIGH65MEDIUM22

Vulnerabilities

Page 5 of 7
CVE-2026-55524P3HIGHCVSS 7.5fixed in 1.6.582026-08-05
CVE-2026-55524 [HIGH] CWE-367 CVE-2026-55524: PraisonAI is a multi-agent teams system. In versions prior to 1.6.58, the web_crawl tool performs it PraisonAI is a multi-agent teams system. In versions prior to 1.6.58, the web_crawl tool performs its SSRF check only on the initially supplied URL, allowing the protection to be bypassed so the tool connects to attacker-chosen internal destinations. The check resolves the hostname once with socket.gethostbyname and rejects private/loopback/link-local
nvd
CVE-2026-61438P3HIGHCVSS 7.3fixed in 4.6.782026-07-15
CVE-2026-61438 [HIGH] CWE-78 CVE-2026-61438: PraisonAI before 4.6.78 contains a remote code execution vulnerability in JobWorkflowExecutor._exec_ PraisonAI before 4.6.78 contains a remote code execution vulnerability in JobWorkflowExecutor._exec_inline_python() due to insufficient AST validation of workflow script steps. Attackers can create malicious YAML workflow files with import os statements followed by os.system() calls that bypass sandbox checks and execute arbitrary OS commands with proc
nvd
CVE-2026-39889P3HIGHCVSS 7.5fixed in 4.5.1152026-04-08
CVE-2026-39889 [HIGH] CWE-200 CVE-2026-39889: PraisonAI is a multi-agent teams system. Prior to 4.5.115, the A2U (Agent-to-User) event stream serv PraisonAI is a multi-agent teams system. Prior to 4.5.115, the A2U (Agent-to-User) event stream server in PraisonAI exposes all agent activity without authentication. The create_a2u_routes() function registers the following endpoints with NO authentication checks: /a2u/info, /a2u/subscribe, /a2u/events/{stream_name}, /a2u/events/sub/{id}, and /a2u/hea
ghsanvdosv
CVE-2026-55538P3HIGHCVSS 7.3fixed in 4.6.582026-08-25
CVE-2026-55538 [HIGH] CWE-306 CVE-2026-55538: PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.51, praisonai serve agents parses co PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.51, praisonai serve agents parses config["api_key"] but _create_agents_app() does not authenticate POST /agents or POST /agents/{agent_name}. Missing or incorrect bearer and X-API-Key values still reach agent execution. This issue is fixed in version 4.6.58.
ghsanvd
CVE-2026-60091P3HIGHCVSS 7.2fixed in 4.6.782026-07-10
CVE-2026-60091 [HIGH] CWE-918 CVE-2026-60091: PraisonAI before 4.6.78 contains an unauthenticated server-side request forgery vulnerability in the PraisonAI before 4.6.78 contains an unauthenticated server-side request forgery vulnerability in the Jobs API /api/v1/runs endpoint. The webhook_url parameter is validated at request time but re-resolved at connection time, allowing attackers to use DNS rebinding to reach internal services with a blind SSRF attack.
nvd
CVE-2026-39308P3HIGHCVSS 7.1fixed in 4.5.1132026-04-07
CVE-2026-39308 [HIGH] CWE-22 CVE-2026-39308: PraisonAI is a multi-agent teams system. Prior to 1.5.113, PraisonAI's recipe registry publish endpo PraisonAI is a multi-agent teams system. Prior to 1.5.113, PraisonAI's recipe registry publish endpoint writes uploaded recipe bundles to a filesystem path derived from the bundle's internal manifest.json before it verifies that the manifest name and version match the HTTP route. A malicious publisher can place ../ traversal sequences in the bundle man
ghsanvdosv
CVE-2026-55525P3HIGHCVSS 7.5fixed in 4.6.582026-08-25
CVE-2026-55525 [HIGH] CWE-918 CVE-2026-55525: PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.58, the web_crawl function val PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.58, the web_crawl function validates only the initial URL before _crawl_with_httpx uses httpx.Client(follow_redirects=True). Redirect targets are not revalidated, so an attacker who influences a crawl target can redirect a public URL to loopback, private network, or cloud metadata s
nvd
CVE-2026-61439P3HIGHCVSS 7.5fixed in 4.6.782026-07-11
CVE-2026-61439 [HIGH] CWE-1188 CVE-2026-61439: PraisonAI versions before 4.6.78 contain a prompt injection defense misconfiguration where the block PraisonAI versions before 4.6.78 contain a prompt injection defense misconfiguration where the block threshold defaults to CRITICAL severity, allowing HIGH-level threats to pass through unblocked. Attackers can submit single-vector prompt injection attacks such as instruction overrides or financial manipulation that trigger HIGH severity detection bu
nvd
CVE-2026-39306P3HIGHCVSS 7.3fixed in 4.5.1132026-04-07
CVE-2026-39306 [HIGH] CWE-22 CVE-2026-39306: PraisonAI is a multi-agent teams system. Prior to 1.5.113, PraisonAI's recipe registry pull flow ext PraisonAI is a multi-agent teams system. Prior to 1.5.113, PraisonAI's recipe registry pull flow extracts attacker-controlled .praison tar archives with tar.extractall() and does not validate archive member paths before extraction. A malicious publisher can upload a recipe bundle that contains ../ traversal entries and any user who later pulls that rec
ghsanvdosv
CVE-2026-44334P3HIGHCVSS 8.4fixed in 4.6.402026-05-08
CVE-2026-44334 [HIGH] CWE-94 CVE-2026-44334: PraisonAI is a multi-agent teams system. From version 4.5.139 to before version 4.6.32, CVE-2026-402 PraisonAI is a multi-agent teams system. From version 4.5.139 to before version 4.6.32, CVE-2026-40287's fix gated tools.py auto-import behind PRAISONAI_ALLOW_LOCAL_TOOLS=true in two files (tool_resolver.py, api/call.py). A third import sink in praisonai/templates/tool_override.py was missed and remains unguarded. It is reached by the recipe runner on
ghsanvd
CVE-2026-39307P3HIGHCVSS 8.1fixed in 4.5.1132026-04-07
CVE-2026-39307 [HIGH] CWE-22 CVE-2026-39307: PraisonAI is a multi-agent teams system. Prior to 1.5.113, The PraisonAI templates installation feat PraisonAI is a multi-agent teams system. Prior to 1.5.113, The PraisonAI templates installation feature is vulnerable to a "Zip Slip" Arbitrary File Write attack. When downloading and extracting template archives from external sources (e.g., GitHub), the application uses Python's zipfile.extractall() without verifying if the files within the archive re
ghsanvdosv
CVE-2026-55532P3HIGHCVSS 7.6fixed in 4.6.582026-08-25
CVE-2026-55532 [HIGH] CWE-346 CVE-2026-55532: PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.58, MCP HTTP Stream _validate_origin PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.58, MCP HTTP Stream _validate_origin uses request_origin.startswith(allowed), allowing the attacker-controlled localhost.attacker.com HTTP origin to satisfy the localhost allowlist. A webpage can send Content-Type: text/plain requests without preflight and invoke tools/call without an API
ghsanvd
CVE-2026-40115P3HIGHCVSS 7.5fixed in 4.5.1282026-04-09
CVE-2026-40115 [HIGH] CWE-770 CVE-2026-40115: PraisonAI is a multi-agent teams system. Prior to 4.5.128, the WSGI-based recipe registry server (se PraisonAI is a multi-agent teams system. Prior to 4.5.128, the WSGI-based recipe registry server (server.py) reads the entire HTTP request body into memory based on the client-supplied Content-Length header with no upper bound. Combined with authentication being disabled by default (no token configured), any local process can send arbitrarily large PO
ghsanvd
CVE-2026-40158P3HIGHCVSS 7.8fixed in 4.5.1282026-04-10
CVE-2026-40158 [HIGH] CWE-94 CVE-2026-40158: PraisonAI is a multi-agent teams system. Prior to 4.5.128, PraisonAI's AST-based Python sandbox can PraisonAI is a multi-agent teams system. Prior to 4.5.128, PraisonAI's AST-based Python sandbox can be bypassed using type.__getattribute__ trampoline, allowing arbitrary code execution when running untrusted agent code. The _execute_code_direct function in praisonaiagents/tools/python_tools.py uses AST filtering to block dangerous Python attributes lik
ghsanvd
CVE-2026-55522P3HIGHCVSS 7.8v>= 3.9.26, < 4.6.582026-08-05
CVE-2026-55522 [HIGH] CWE-94 CVE-2026-55522: PraisonAI is a multi-agent teams system. In versions 3.9.26 through 4.6.57 of praiseonai and 0.12.12 PraisonAI is a multi-agent teams system. In versions 3.9.26 through 4.6.57 of praiseonai and 0.12.12 through 1.6.57 of praiseonaiagents, the workflow "include" feature is vulnerable to code execution. Workflow._execute_include() implicitly imports and runs an included recipe's tools.py via a raw importlib.util.spec_from_file_location() and spec.loader.
ghsanvd
CVE-2026-61433P3HIGHCVSS 7.8fixed in 4.6.782026-07-15
CVE-2026-61433 [HIGH] CWE-94 CVE-2026-61433: PraisonAI before 4.6.78 fails to safely encode deployment configuration values when generating Pytho PraisonAI before 4.6.78 fails to safely encode deployment configuration values when generating Python source code for API servers. Attackers can inject arbitrary Python expressions through the deploy.api.host and agents_file configuration parameters that execute when the generated server starts or handles requests.
nvd
CVE-2026-56839P3HIGHCVSS 7.3fixed in 4.6.592026-09-14
CVE-2026-56839 [HIGH] CWE-22 CVE-2026-56839: PraisonAI is a multi-agent teams system. Prior to 4.6.59, the CODE_TOOLS wrappers keep _workspace_ro PraisonAI is a multi-agent teams system. Prior to 4.6.59, the CODE_TOOLS wrappers keep _workspace_root as None and pass workspace=None to read_file, search_replace, and apply_diff helpers that enforce path containment only for a truthy workspace. An application that exposes code_read_file, code_search_replace, or code_apply_diff before set_workspace ca
nvd
CVE-2026-47397P3HIGHCVSS 7.1fixed in 4.6.402026-07-21
CVE-2026-47397 [HIGH] CWE-22 CVE-2026-47397: PraisonAI is a multi-agent teams system. Prior to version 4.6.40, hidden metadata in a webpage cause PraisonAI is a multi-agent teams system. Prior to version 4.6.40, hidden metadata in a webpage causes PraisonAI agents to write attacker-controlled content to arbitrary paths. `write_file` skips path validation when `workspace=None` (always `None` in production). Version 4.6.40 fixes the issue.
ghsanvd
CVE-2026-40156P3HIGHCVSS 7.8fixed in 4.5.1282026-04-10
CVE-2026-40156 [HIGH] CWE-94 CVE-2026-40156: PraisonAI is a multi-agent teams system. Prior to 4.5.128, PraisonAI automatically loads a file name PraisonAI is a multi-agent teams system. Prior to 4.5.128, PraisonAI automatically loads a file named tools.py from the current working directory to discover and register custom agent tools. This loading process uses importlib.util.spec_from_file_location and immediately executes module-level code via spec.loader.exec_module() without explicit user con
ghsanvd
CVE-2026-61437P3HIGHCVSS 7.8fixed in 1.6.782026-07-10
CVE-2026-61437 [HIGH] CWE-693 CVE-2026-61437: PraisonAI (pip package praisonaiagents) before 1.6.78 contains an unsafe dynamic module loading vuln PraisonAI (pip package praisonaiagents) before 1.6.78 contains an unsafe dynamic module loading vulnerability in AgentFlow._resolve_pydantic_class (src/praisonai-agents/praisonaiagents/workflows/workflows.py). When a workflow step uses a string output_pydantic reference, the framework locates and imports a sibling tools.py from the workflow file's dir
nvd
Mervinpraison Praisonai vulnerabilities | cvebase