Mervinpraison Praisonai vulnerabilities
127 known vulnerabilities affecting mervinpraison/praisonai.
Total CVEs
127
CISA KEV
0
Public exploits
3
Exploited in wild
1
Severity breakdown
CRITICAL40HIGH65MEDIUM22
Vulnerabilities
Page 7 of 7
CVE-2026-60087P4MEDIUMCVSS 6.1fixed in 1.6.782026-07-15
CVE-2026-60087 [MEDIUM] CWE-863 CVE-2026-60087: PraisonAI before 1.6.78 caches tool approval decisions by tool name only, allowing attackers to reus
PraisonAI before 1.6.78 caches tool approval decisions by tool name only, allowing attackers to reuse initial approvals for subsequent calls with arbitrary arguments. Attackers can exploit this by obtaining approval for a benign operation and then executing dangerous file write operations with unreviewed parameters in the same session.
nvd
CVE-2026-47390P4MEDIUMCVSS 5.5fixed in 4.6.402026-07-21
CVE-2026-47390 [MEDIUM] CWE-918 CVE-2026-47390: PraisonAI is a multi-agent teams system. Prior to version 4.6.40 of PraisonAI, corresponding to vers
PraisonAI is a multi-agent teams system. Prior to version 4.6.40 of PraisonAI, corresponding to version 1.6.40 of praisonaiagents, `spider_tools` URL validation can be bypassed using alternate loopback host encodings. The tool contains a URL validation function intended to block local or unsafe targets before fetching attacker-controlled URLs. Howev
ghsanvd
CVE-2026-60088P4MEDIUMCVSS 5.5fixed in 4.6.782026-07-11
CVE-2026-60088 [MEDIUM] CWE-22 CVE-2026-60088: PraisonAI before 4.6.78 fails to validate file path references in custom command templates, allowing
PraisonAI before 4.6.78 fails to validate file path references in custom command templates, allowing attackers to read files outside the workspace. Attackers can include path traversal sequences like @../outside_secret.txt or absolute paths in project command files to exfiltrate process-readable files into model prompts.
nvd
CVE-2026-55530P4MEDIUMCVSS 6.1fixed in 4.6.582026-08-25
CVE-2026-55530 [MEDIUM] CWE-862 CVE-2026-55530: PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.58, ast_grep_rewrite lacks the
PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.58, ast_grep_rewrite lacks the @require_approval decorator used by sibling mutation tools. With dry_run=False, an agent-controlled call can pass --update-all and a broad path to rewrite matching files without the expected authorization gate. This issue is fixed in version 1.6.58.
nvd
CVE-2026-47395P4MEDIUMCVSS 5.5fixed in 4.6.402026-07-21
CVE-2026-47395 [MEDIUM] CWE-200 CVE-2026-47395: PraisonAI is a multi-agent teams system. Prior to version 4.6.40 of PraisonAI, corresponding to vers
PraisonAI is a multi-agent teams system. Prior to version 4.6.40 of PraisonAI, corresponding to version 1.6.40 of praisonaiagents, PraisonAI's direct-prompt CLI automatically expands `@url:` mentions in raw prompt text before agent execution begins. If a prompt contains `@url:`, the CLI calls `MentionsParser.process(...)`. The `@url:` handler then p
ghsanvd
CVE-2026-60089P4MEDIUMCVSS 5.5fixed in 1.6.782026-07-10
CVE-2026-60089 [MEDIUM] CWE-22 CVE-2026-60089: PraisonAI (pip package praisonaiagents) before 1.6.78 automatically loads defaults from a project-lo
PraisonAI (pip package praisonaiagents) before 1.6.78 automatically loads defaults from a project-local .praisonai/config.toml when constructing an Agent, and does not validate the defaults.output.output_file path. A repository-controlled config file can set output_file to an absolute or '..' traversal path; when the developer subsequently calls agen
nvd
CVE-2026-57128P4MEDIUMCVSS 4.3fixed in 1.6.582026-09-14
CVE-2026-57128 [MEDIUM] CWE-306 CVE-2026-57128: PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.58, the SSE server in src/prai
PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.58, the SSE server in src/praisonai-agents/praisonaiagents/server/server.py does not consult ServerConfig.auth_token before handling /publish, /events, or /info requests. A network client that can reach the server can broadcast arbitrary events to connected clients and obtain serv
nvd
← Previous7 / 7