cbcvebase.

Mervinpraison Praisonaiagents vulnerabilities

35 known vulnerabilities affecting mervinpraison/praisonaiagents.

Total CVEs
35
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL7HIGH19MEDIUM9

Vulnerabilities

Page 1 of 2
CVE-2026-57125P2CRITICALCVSS 9.8fixed in 1.6.592026-09-14
CVE-2026-57125 [CRITICAL] CWE-306 CVE-2026-57125: PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.59 and praisonaiagents 1.6.59, the u PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.59 and praisonaiagents 1.6.59, the unauthenticated POST /api/v1/runs Jobs API accepts attacker-controlled agent_yaml, and the approve field can mark execute_command as YAML-approved before @require_approval checks critical tools. This chain allows a remote caller to cause a configured
nvd
CVE-2026-40288P2CRITICALCVSS 9.8fixed in 1.5.1402026-04-14
CVE-2026-40288 [CRITICAL] CWE-78 CVE-2026-40288: PraisonAI is a multi-agent teams system. In versions below 4.5.139 of PraisonAI and 1.5.140 of prais PraisonAI is a multi-agent teams system. In versions below 4.5.139 of PraisonAI and 1.5.140 of praisonaiagents, the workflow engine is vulnerable to arbitrary command and code execution through untrusted YAML files. When praisonai workflow run loads a YAML file with type: job, the JobWorkflowExecutor in job_workflow.py processes steps that support
ghsanvd
CVE-2026-34938P2CRITICAL≥ 0, < 1.5.902026-04-01
CVE-2026-34938 [CRITICAL] CWE-693 PraisonAI: Python Sandbox Escape via str Subclass startswith() Override in execute_code PraisonAI: Python Sandbox Escape via str Subclass startswith() Override in execute_code ### Summary `execute_code()` in `praisonai-agents` runs attacker-controlled Python inside a three-layer sandbox that can be fully bypassed by passing a `str` subclass with an overridden `startswith()` method to the `_safe_getattr` wrapper, achieving arbitrary OS command execution on the
ghsaosv
CVE-2026-47392P2CRITICALCVSS 10.0≥ 0, < 1.6.402026-05-29
CVE-2026-47392 [CRITICAL] CWE-184 PraisonAI vulnerable to sandbox escape via `print.__self__` builtins module leak in `execute_code` (subprocess mode) PraisonAI vulnerable to sandbox escape via `print.__self__` builtins module leak in `execute_code` (subprocess mode) ## Summary `execute_code()` in `praisonaiagents/tools/python_tools.py` (v1.6.37, subprocess sandbox mode) can be fully bypassed using `print.__self__` to retrieve the real Python `builtins` module, from which `__import__` can be e
ghsa
CVE-2026-57123P2CRITICALCVSS 9.8fixed in 1.6.592026-09-14
CVE-2026-57123 [CRITICAL] CWE-306 CVE-2026-57123: PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.59, ToolsMCPServer.run_sse and PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.59, ToolsMCPServer.run_sse and launch_tools_mcp_server bind to 0.0.0.0 and create /sse and /messages/ routes without invoking the available SecurityConfig authentication, origin-validation, or DNS-rebinding controls. Any reachable client can list and invoke registered tools, and
nvd
CVE-2026-39888P3CRITICALCVSS 9.9fixed in 1.5.1152026-04-08
CVE-2026-39888 [CRITICAL] CWE-657 CVE-2026-39888: PraisonAI is a multi-agent teams system. Prior to 1.5.115, execute_code() in praisonaiagents.tools.p PraisonAI is a multi-agent teams system. Prior to 1.5.115, execute_code() in praisonaiagents.tools.python_tools defaults to sandbox_mode="sandbox", which runs user code in a subprocess wrapped with a restricted __builtins__ dict and an AST-based blocklist. The AST blocklist embedded inside the subprocess wrapper (blocked_attrs of python_tools.py)
ghsanvdosv
CVE-2026-40289P2CRITICAL≥ 0, < 1.5.1402026-04-10
CVE-2026-40289 [CRITICAL] CWE-306 PraisonAI Browser Server allows unauthenticated WebSocket clients to hijack connected extension sessions PraisonAI Browser Server allows unauthenticated WebSocket clients to hijack connected extension sessions ### Summary `praisonai browser start` exposes the browser bridge on `0.0.0.0` by default, and its `/ws` endpoint accepts websocket clients that omit the `Origin` header entirely. An unauthenticated network client can connect as a fake controller, send `st
ghsa
CVE-2026-34937P2HIGH≥ 0, < 1.5.902026-04-01
CVE-2026-34937 [HIGH] CWE-78 PraisonAI: Shell Injection in run_python() via Unescaped $() Substitution PraisonAI: Shell Injection in run_python() via Unescaped $() Substitution ### Summary `run_python()` in `praisonai` constructs a shell command string by interpolating user-controlled code into `python3 -c ""` and passing it to `subprocess.run(..., shell=True)`. The escaping logic only handles `\` and `"`, leaving `$()` and backtick substitutions unescaped, allowing arbitrary OS command execut
ghsaosv
CVE-2026-40315P3HIGH≥ 0, < 1.6.82026-04-17
CVE-2026-40315 [HIGH] CWE-89 PraisonAI: SQL Injection via unvalidated `table_prefix` in 9 conversation store backends (incomplete fix for CVE-2026-40315) PraisonAI: SQL Injection via unvalidated `table_prefix` in 9 conversation store backends (incomplete fix for CVE-2026-40315) The fix for [CVE-2026-40315](https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-x783-xp3g-mqhp) added input validation to `SQLiteConversationStore` only. Nine sibling backends — MySQL, PostgreSQL, async
ghsa
CVE-2026-40111P3HIGHCVSS 8.8fixed in 1.5.1282026-04-09
CVE-2026-40111 [HIGH] CWE-78 CVE-2026-40111: PraisonAIAgents is a multi-agent teams system. Prior to 1.5.128, he memory hooks executor in praison PraisonAIAgents is a multi-agent teams system. Prior to 1.5.128, he memory hooks executor in praisonaiagents passes a user-controlled command string directly to subprocess.run() with shell=True at src/praisonai-agents/praisonaiagents/memory/hooks.py. No sanitization is performed and shell metacharacters are interpreted by /bin/sh before the intended co
ghsanvd
CVE-2026-44335P3HIGH≥ 0, < 1.6.322026-05-06
CVE-2026-44335 [HIGH] CWE-918 PraisonAI has an SSRF bypass PraisonAI has an SSRF bypass ### Summary The URL checking logic in PraisonAI has a logical flaw that could be bypassed by attackers, leading to SSRF attacks. ### Details The current PraisonAI project uses _validate_url to validate the input URL. The main logic is to perform security checks on the host portion of the URL extracted by urlparse to prevent SSRF attacks. However, there are indeed differences in parsing between urlparse an
ghsa
CVE-2026-55526P3HIGHCVSS 8.5fixed in 1.6.582026-08-25
CVE-2026-55526 [HIGH] CWE-350 CVE-2026-55526: PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.58, spider_tools._host_is_bloc PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.58, spider_tools._host_is_blocked() does not resolve ordinary hostnames before scrape_page fetches them. A hostname such as 127.0.0.1.nip.io passes validation and resolves to loopback, permitting internal HTTP access. The fix uses socket.getaddrinfo and fails closed on DNS errors. T
ghsanvd
CVE-2026-57129P3HIGHCVSS 7.5fixed in 1.6.592026-09-14
CVE-2026-57129 [HIGH] CWE-22 CVE-2026-57129: PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.59, MentionsParser._process_fi PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.59, MentionsParser._process_file_mention accepts file-mention values and falls back from workspace-relative resolution to Path(file_path) without traversal, symlink, or workspace-boundary validation. Prompt input from users, bots, or workflows can therefore read arbitrary files acces
nvd
CVE-2026-57130P3HIGHCVSS 8.1fixed in 1.6.592026-09-14
CVE-2026-57130 [HIGH] CWE-20 CVE-2026-57130: PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.59, src/praisonai-agents/prais PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.59, src/praisonai-agents/praisonaiagents/tools/email_tools.py interpolates LLM-controlled from_addr, subject, and query values directly into quoted IMAP SEARCH criteria. Embedded quote, backslash, newline, or null characters can escape the intended criterion and alter IMAP operations
nvd
CVE-2026-34954P3HIGH≥ 0, < 1.5.952026-04-01
CVE-2026-34954 [HIGH] CWE-918 PraisonAI Has SSRF in FileTools.download_file() via Unvalidated URL PraisonAI Has SSRF in FileTools.download_file() via Unvalidated URL ### Summary `FileTools.download_file()` in `praisonaiagents` validates the destination path but performs no validation on the `url` parameter, passing it directly to `httpx.stream()` with `follow_redirects=True`. An attacker who controls the URL can reach any host accessible from the server including cloud metadata services and in
ghsaosv
CVE-2026-55528P3HIGHCVSS 8.2fixed in 1.6.582026-08-25
CVE-2026-55528 [HIGH] CWE-306 CVE-2026-55528: PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.58, AgentServer exposes Server PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.58, AgentServer exposes ServerConfig.auth_token but AgentServer._create_app does not check it on any route. A remote caller can subscribe, publish, and perform other actions without a valid bearer token or X-Auth-Token even when authentication is configured. This issue is fixed in v
ghsanvd
CVE-2026-40117P3HIGHCVSS 7.5fixed in 1.5.1282026-04-09
CVE-2026-40117 [HIGH] CWE-862 CVE-2026-40117: PraisonAIAgents is a multi-agent teams system. Prior to 1.5.128, read_skill_file() in skill_tools.py PraisonAIAgents is a multi-agent teams system. Prior to 1.5.128, read_skill_file() in skill_tools.py allows reading arbitrary files from the filesystem by accepting an unrestricted skill_path parameter. Unlike file_tools.read_file which enforces workspace boundary confinement, and unlike run_skill_script which requires critical-level approval, read_sk
ghsanvd
CVE-2026-55523P3MEDIUMCVSS 6.5≥ 1.5.128, < 1.6.582026-08-25
CVE-2026-55523 [MEDIUM] CWE-918 praisonaiagents has a `web_crawl` SSRF protection bypass via unchecked redirect targets praisonaiagents has a `web_crawl` SSRF protection bypass via unchecked redirect targets ## Summary `praisonaiagents.tools.web_crawl_tools.web_crawl()` validates the initial URL and blocks direct loopback/private destinations by default, but the default httpx fallback still uses `httpx.Client(follow_redirects=True)` and does not revalidate redirect targets. An attacker-contro
ghsa
CVE-2026-57112P3HIGHCVSS 8.3v>= 0.6.0, < 1.6.592026-09-15
CVE-2026-57112 [HIGH] CWE-306 CVE-2026-57112: PraisonAI is a multi-agent teams system. From praisonaiagents 0.6.0 until 1.6.59 and PraisonAI 3.10. PraisonAI is a multi-agent teams system. From praisonaiagents 0.6.0 until 1.6.59 and PraisonAI 3.10.0 until 4.6.59, ToolsMCPServer.run_sse() in src/praisonai-agents/praisonaiagents/mcp/mcp_server.py mounts SseServerTransport on the legacy /sse and /messages/ endpoints without default Host, Origin, or authentication enforcement. A malicious website can
nvd
CVE-2025-66416P3HIGH≥ 0.6.0, < 1.6.592026-06-18
CVE-2025-66416 [HIGH] CWE-306 PraisonAI ToolsMCPServer legacy SSE transport accepts attacker Host/Origin and exposes registered tools PraisonAI ToolsMCPServer legacy SSE transport accepts attacker Host/Origin and exposes registered tools # PraisonAI ToolsMCPServer legacy SSE transport accepts attacker Host/Origin and exposes registered tools ## Summary `praisonaiagents.mcp.ToolsMCPServer.run_sse()` builds a Starlette MCP HTTP+SSE server around `mcp.server.sse.SseServerTransport`. The server e
ghsa
Mervinpraison Praisonaiagents vulnerabilities | cvebase