Mervinpraison Praisonai vulnerabilities
127 known vulnerabilities affecting mervinpraison/praisonai.
Total CVEs
127
CISA KEV
0
Public exploits
3
Exploited in wild
1
Severity breakdown
CRITICAL40HIGH65MEDIUM22
Vulnerabilities
Page 6 of 7
CVE-2026-40149P3HIGHCVSS 7.3fixed in 4.5.1282026-04-09
CVE-2026-40149 [HIGH] CWE-396 CVE-2026-40149: PraisonAI is a multi-agent teams system. Prior to 4.5.128, the gateway's /api/approval/allow-list en
PraisonAI is a multi-agent teams system. Prior to 4.5.128, the gateway's /api/approval/allow-list endpoint permits unauthenticated modification of the tool approval allowlist when no auth_token is configured (the default). By adding dangerous tool names (e.g., shell_exec, file_write) to the allowlist, an attacker can cause the ExecApprovalManager to a
ghsanvd
CVE-2026-55527P3HIGHCVSS 7.1fixed in 1.6.582026-08-25
CVE-2026-55527 [HIGH] CWE-22 CVE-2026-55527: PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.58, the FileMemory constructor
PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.58, the FileMemory constructor joins unsanitized user_id into self.user_path. A caller supplying ../ or path separators can escape the memory directory and write JSON data to arbitrary process-writable locations. The fix sanitizes user_id before constructing self.user_path. This issu
nvd
CVE-2026-44337P3MEDIUMCVSS 6.3v>= 2.4.1, < 4.6.342026-05-08
CVE-2026-44337 [MEDIUM] CWE-20 CVE-2026-44337: PraisonAI is a multi-agent teams system. From version 2.4.1 to before version 4.6.34, PraisonAI expo
PraisonAI is a multi-agent teams system. From version 2.4.1 to before version 4.6.34, PraisonAI exposes optional SQL/CQL-backed knowledge-store implementations that build table and index identifiers from unvalidated name and collection arguments. Applications that pass untrusted collection names into these backends can trigger SQL or CQL injection. T
ghsanvd
CVE-2026-34939P3HIGHCVSS 7.5fixed in 4.5.902026-04-03
CVE-2026-34939 [HIGH] CWE-1333 CVE-2026-34939: PraisonAI is a multi-agent teams system. Prior to version 4.5.90, MCPToolIndex.search_tools() compil
PraisonAI is a multi-agent teams system. Prior to version 4.5.90, MCPToolIndex.search_tools() compiles a caller-supplied string directly as a Python regular expression with no validation, sanitization, or timeout. A crafted regex causes catastrophic backtracking in the re engine, blocking the Python thread for hundreds of seconds and causing a comple
ghsanvdosv
CVE-2026-55540P3HIGHCVSS 7.1fixed in 4.6.582026-08-25
CVE-2026-55540 [HIGH] CWE-22 CVE-2026-55540: PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.51, is_path_within_directory() uses
PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.51, is_path_within_directory() uses os.path.abspath() rather than os.path.realpath() for the workspace boundary. A symlink inside workspace can point outside and still pass the check, allowing read_file and other code tools to access files outside the configured workspace. This issue is fix
ghsanvd
CVE-2026-61441P3MEDIUMCVSS 6.5fixed in 0.1.92026-07-10
CVE-2026-61441 [MEDIUM] CWE-862 CVE-2026-61441: PraisonAI Platform (praisonai-platform) before 0.1.9 improperly authorizes deletion of issue depende
PraisonAI Platform (praisonai-platform) before 0.1.9 improperly authorizes deletion of issue dependencies. The DELETE dependency route accepts either endpoint of a dependency edge and checks delete permission only against the caller-selected URL issue. A workspace member who cannot delete a dependency through an owner-created issue endpoint (which r
nvd
CVE-2026-61442P3HIGHCVSS 7.1fixed in 0.1.92026-07-11
CVE-2026-61442 [HIGH] CWE-862 CVE-2026-61442: PraisonAI Platform (praisonai-platform) before 0.1.9 fails to enforce owner/admin authorization on t
PraisonAI Platform (praisonai-platform) before 0.1.9 fails to enforce owner/admin authorization on the PATCH routes for projects, issues, and agents, which only require workspace-member role. A workspace member can modify owner-created records; for projects, a member can reassign lead_id to their own user id and then delete the owner-created project,
nvd
CVE-2026-55537P3CRITICALCVSS 10.0≥ 0, < 4.6.582026-08-25
CVE-2026-55537 [CRITICAL] CWE-367 PraisonAI: Webhook SSRF via DNS fail-open in `JobSubmitRequest.validate_webhook_url()` — bypass of CVE-2026-40114
PraisonAI: Webhook SSRF via DNS fail-open in `JobSubmitRequest.validate_webhook_url()` — bypass of CVE-2026-40114
### Summary
`praisonai/jobs/models.py::JobSubmitRequest.validate_webhook_url()` validates webhook
URLs by resolving the hostname and checking whether the IP is private. When DNS
resolution fails (`socket.gaierror`), the validator **sile
ghsa
CVE-2026-61440P3MEDIUMCVSS 6.5fixed in 0.1.92026-07-15
CVE-2026-61440 [MEDIUM] CWE-862 CVE-2026-61440: PraisonAI Platform before 0.1.9 fails to properly authorize label and issue-label mutations, allowin
PraisonAI Platform before 0.1.9 fails to properly authorize label and issue-label mutations, allowing workspace members to rename and recolor shared labels and add or remove labels on owner-created issues. Attackers with workspace member privileges can exploit PATCH and POST/DELETE endpoints to alter shared label taxonomy and manipulate issue-label
nvd
CVE-2026-55529P3MEDIUMCVSS 6.9fixed in 4.6.582026-08-25
CVE-2026-55529 [MEDIUM] CWE-306 CVE-2026-55529: PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.58, the MCP HTTP Stream _validate_or
PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.58, the MCP HTTP Stream _validate_origin method accepts request_origin.startswith(allowed), so the attacker-controlled localhost.evil.example HTTP origin matches the localhost allowlist. Without an API key, a malicious webpage can submit tools/call requests to the local MCP server and e
ghsanvd
CVE-2026-55535P3MEDIUMCVSS 6.8fixed in 4.6.582026-08-25
CVE-2026-55535 [MEDIUM] CWE-367 CVE-2026-55535: PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.58, the Jobs API validate_webhook_ur
PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.58, the Jobs API validate_webhook_url() path fails open on socket.gaierror and does not bind the validated address to the later request. An attacker webhook_url can later resolve to 127.0.0.1, 169.254.169.254, or another internal address. This issue is fixed in version 4.6.58.
ghsanvd
CVE-2026-40160P3MEDIUMCVSS 6.5v>= 1.5.128, < 1.6.582026-04-10
CVE-2026-40160 [MEDIUM] CWE-918 CVE-2026-40160: PraisonAIAgents is a multi-agent teams system. Prior to 1.5.128, web_crawl's httpx fallback path pas
PraisonAIAgents is a multi-agent teams system. Prior to 1.5.128, web_crawl's httpx fallback path passes user-supplied URLs directly to httpx.AsyncClient.get() with follow_redirects=True and no host validation. An LLM agent tricked into crawling an internal URL can reach cloud metadata endpoints (169.254.169.254), internal services, and localhost. Th
nvd
CVE-2026-55531P4MEDIUMCVSS 6.5fixed in 4.6.582026-08-25
CVE-2026-55531 [MEDIUM] CWE-400 CVE-2026-55531: PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.58, the MCP HTTP Stream mcp_post han
PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.58, the MCP HTTP Stream mcp_post handler creates a new _sessions entry for every initialize request but does not call _cleanup_sessions or enforce a maximum. An unauthenticated caller can exhaust memory. The fix invokes cleanup and limits sessions through PRAISONAI_MCP_MAX_SESSIONS. Thi
ghsanvd
CVE-2026-57115P4MEDIUMCVSS 6.5fixed in 4.6.592026-09-14
CVE-2026-57115 [MEDIUM] CWE-918 CVE-2026-57115: PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.59, SpiderTools.scrape_page va
PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.59, SpiderTools.scrape_page validates only the initial URL and lets requests.Session.get follow redirects automatically, so a public-looking URL can redirect to a loopback, private, link-local, or metadata address without revalidation. The redirected response body is returned thro
nvd
CVE-2026-61432P4MEDIUMCVSS 5.7fixed in 1.6.782026-07-10
CVE-2026-61432 [MEDIUM] CWE-22 CVE-2026-61432: PraisonAI (praisonaiagents) before 1.6.78 contains a path traversal vulnerability in the FastContext
PraisonAI (praisonaiagents) before 1.6.78 contains a path traversal vulnerability in the FastContext feature (praisonaiagents.context.fast). FastContextAgent.execute_tool() prepends the configured workspace_path only for relative paths and neither rejects absolute paths nor canonicalizes joined paths before enforcing workspace containment. As a resul
nvd
CVE-2026-40148P4MEDIUMCVSS 6.5fixed in 4.5.1282026-04-09
CVE-2026-40148 [MEDIUM] CWE-409 CVE-2026-40148: PraisonAI is a multi-agent teams system. Prior to 4.5.128, the _safe_extractall() function in Praiso
PraisonAI is a multi-agent teams system. Prior to 4.5.128, the _safe_extractall() function in PraisonAI's recipe registry validates archive members against path traversal attacks but performs no checks on individual member sizes, cumulative extracted size, or member count before calling tar.extractall(). An attacker can publish a malicious recipe bu
ghsanvd
CVE-2026-40112P4MEDIUMCVSS 6.1fixed in 4.5.1282026-04-09
CVE-2026-40112 [MEDIUM] CWE-79 CVE-2026-40112: PraisonAI is a multi-agent teams system. Prior to 4.5.128, the Flask API endpoint in src/praisonai/a
PraisonAI is a multi-agent teams system. Prior to 4.5.128, the Flask API endpoint in src/praisonai/api.py renders agent output as HTML without effective sanitization. The _sanitize_html function relies on the nh3 library, which is not listed as a required or optional dependency in pyproject.toml. When nh3 is absent (the default installation), the san
ghsanvd
CVE-2026-61431P4MEDIUMCVSS 5.5fixed in 4.6.782026-07-10
CVE-2026-61431 [MEDIUM] CWE-22 CVE-2026-61431: PraisonAI before 4.6.78 contains a path traversal vulnerability in ContextGatherer that fails to val
PraisonAI before 4.6.78 contains a path traversal vulnerability in ContextGatherer that fails to validate include paths in .praisoncontext and .praisoninclude files. Attackers can supply absolute paths or parent directory traversal sequences to read arbitrary files outside the workspace and include their contents in the generated context bundle.
nvd
CVE-2026-40159P4MEDIUMCVSS 5.5fixed in 4.5.1282026-04-10
CVE-2026-40159 [MEDIUM] CWE-200 CVE-2026-40159: PraisonAI is a multi-agent teams system. Prior to 4.5.128, PraisonAI’s MCP (Model Context Protocol)
PraisonAI is a multi-agent teams system. Prior to 4.5.128, PraisonAI’s MCP (Model Context Protocol) integration allows spawning background servers via stdio using user-supplied command strings (e.g., MCP("npx -y @smithery/cli ...")). These commands are executed through Python’s subprocess module. By default, the implementation forwards the entire par
ghsanvd
CVE-2026-60086P4MEDIUMCVSS 5.3fixed in 4.6.782026-07-10
CVE-2026-60086 [MEDIUM] CWE-693 CVE-2026-60086: PraisonAI before 4.6.78 contains a prompt injection defense bypass vulnerability where the injection
PraisonAI before 4.6.78 contains a prompt injection defense bypass vulnerability where the injection defense only blocks threats classified as CRITICAL, requiring three or more detector families to match simultaneously. Attackers can craft single or double-vector prompt injections that are classified as HIGH threat level and pass through unblocked t
nvd