cbcvebase.

Mervinpraison Praisonaiagents vulnerabilities

35 known vulnerabilities affecting mervinpraison/praisonaiagents.

Total CVEs
35
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL7HIGH19MEDIUM9

Vulnerabilities

Page 2 of 2
CVE-2026-44339P3HIGH≥ 0, < 1.6.372026-05-11
CVE-2026-44339 [HIGH] CWE-470 PraisonAI has unsafe tool resolution in `ToolExecutionMixin.execute_tool`: undeclared `__main__` callables execute PraisonAI has unsafe tool resolution in `ToolExecutionMixin.execute_tool`: undeclared `__main__` callables execute ### Summary `praisonaiagents` resolves unresolved tool names against module globals and `__main__` after it fails to match the declared tool list and the registry. With the default agent configuration, `_perm_allow` is `None`, so undeclare
ghsa
CVE-2026-40287P3HIGH≥ 0, < 1.5.1402026-04-10
CVE-2026-40287 [HIGH] CWE-426 PraisonAI Vulnerable to RCE via Automatic tools.py Import PraisonAI Vulnerable to RCE via Automatic tools.py Import PraisonAI automatically imports `./tools.py` from the current working directory when launching certain components. This includes call.py, tool_resolver.py, and CLI tool-loading paths. A malicious tools.py placed in the process working directory is executed immediately, allowing arbitrary Python code execution in the host environment. ### Affected Co
ghsa
CVE-2026-55525P3HIGHCVSS 7.5fixed in 1.6.582026-08-25
CVE-2026-55525 [HIGH] CWE-918 CVE-2026-55525: PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.58, the web_crawl function val PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.58, the web_crawl function validates only the initial URL before _crawl_with_httpx uses httpx.Client(follow_redirects=True). Redirect targets are not revalidated, so an attacker who influences a crawl target can redirect a public URL to loopback, private network, or cloud metadata s
ghsanvd
CVE-2026-55524P3HIGH≥ 0, < 1.6.582026-08-25
CVE-2026-55524 [HIGH] CWE-367 praisonaiagents vulnerable to SSRF in web_crawl tool via redirect-following and DNS rebinding (validate-then-fetch gap) praisonaiagents vulnerable to SSRF in web_crawl tool via redirect-following and DNS rebinding (validate-then-fetch gap) The web_crawl tool performs its SSRF check only on the initial URL: it resolves the hostname once with socket.gethostbyname and rejects private/loopback/link-local results. It then passes the URL to a fetcher that uses httpx.Clie
ghsa
CVE-2026-55522P3HIGHCVSS 7.8v>= 0.12.12, < 1.6.582026-08-05
CVE-2026-55522 [HIGH] CWE-94 CVE-2026-55522: PraisonAI is a multi-agent teams system. In versions 3.9.26 through 4.6.57 of praiseonai and 0.12.12 PraisonAI is a multi-agent teams system. In versions 3.9.26 through 4.6.57 of praiseonai and 0.12.12 through 1.6.57 of praiseonaiagents, the workflow "include" feature is vulnerable to code execution. Workflow._execute_include() implicitly imports and runs an included recipe's tools.py via a raw importlib.util.spec_from_file_location() and spec.loader.
ghsanvd
CVE-2026-40150P3MEDIUMCVSS 6.5fixed in 1.5.1282026-04-09
CVE-2026-40150 [MEDIUM] CWE-918 CVE-2026-40150: PraisonAIAgents is a multi-agent teams system. Prior to 1.5.128, the web_crawl() function in praison PraisonAIAgents is a multi-agent teams system. Prior to 1.5.128, the web_crawl() function in praisonaiagents/tools/web_crawl_tools.py accepts arbitrary URLs from AI agents with zero validation. No scheme allowlisting, hostname/IP blocklisting, or private network checks are applied before fetching. This allows an attacker (or prompt injection in craw
ghsanvd
CVE-2026-57120P3MEDIUMCVSS 6.5fixed in 1.6.592026-09-14
CVE-2026-57120 [MEDIUM] CWE-693 CVE-2026-57120: PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.59, execute_code sandbox mode PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.59, execute_code sandbox mode permits runtime assembly of blocklisted dunder names and allows str.format or str.format_map to resolve dotted fields through C-level attribute access that bypasses _safe_getattr. This exposes class, qualified-name, base-class, globals, and object-dict
nvd
CVE-2026-55527P3HIGH≥ 0, < 1.6.582026-08-25
CVE-2026-55527 [HIGH] CWE-22 praisonaiagents vulnerable to arbitrary file write via unsanitized `user_id` in `FileMemory.__init__()` — path traversal to any writable location praisonaiagents vulnerable to arbitrary file write via unsanitized `user_id` in `FileMemory.__init__()` — path traversal to any writable location ### Summary `praisonaiagents/memory/file_memory.py::FileMemory.__init__()` constructs all memory file paths by directly joining the `user_id` parameter to a base path: ```pytho
ghsa
CVE-2026-40153P3MEDIUMCVSS 6.5fixed in 1.5.1282026-04-09
CVE-2026-40153 [MEDIUM] CWE-526 CVE-2026-40153: PraisonAIAgents is a multi-agent teams system. Prior to 1.5.128, the execute_command function in she PraisonAIAgents is a multi-agent teams system. Prior to 1.5.128, the execute_command function in shell_tools.py calls os.path.expandvars() on every command argument at line 64, manually re-implementing shell-level environment variable expansion despite using shell=False (line 88) for security. This allows exfiltration of secrets stored in environmen
ghsanvd
CVE-2026-40152P3MEDIUMCVSS 5.3fixed in 1.5.1282026-04-09
CVE-2026-40152 [MEDIUM] CWE-22 CVE-2026-40152: PraisonAIAgents is a multi-agent teams system. Prior to 1.5.128, he list_files() tool in FileTools v PraisonAIAgents is a multi-agent teams system. Prior to 1.5.128, he list_files() tool in FileTools validates the directory parameter against workspace boundaries via _validate_path(), but passes the pattern parameter directly to Path.glob() without any validation. Since Python's Path.glob() supports .. path segments, an attacker can use relative path
ghsanvd
CVE-2026-57115P4MEDIUMCVSS 6.5fixed in 1.6.592026-09-14
CVE-2026-57115 [MEDIUM] CWE-918 CVE-2026-57115: PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.59, SpiderTools.scrape_page va PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.59, SpiderTools.scrape_page validates only the initial URL and lets requests.Session.get follow redirects automatically, so a public-looking URL can redirect to a loopback, private, link-local, or metadata address without revalidation. The redirected response body is returned thro
nvd
CVE-2026-40160P3HIGH≥ 0.13.23, < 1.5.1282026-04-10
CVE-2026-40160 [HIGH] CWE-918 PraisonAIAgents: SSRF via unvalidated URL in `web_crawl` httpx fallback PraisonAIAgents: SSRF via unvalidated URL in `web_crawl` httpx fallback | Field | Value | |---|---| | Severity | High | | Type | SSRF -- unvalidated URL in `web_crawl` httpx fallback allows internal network access | | Affected | `src/praisonai-agents/praisonaiagents/tools/web_crawl_tools.py:133-180` | ## Summary `web_crawl`'s httpx fallback path passes user-supplied URLs directly to `httpx.As
ghsa
CVE-2026-47390P4MEDIUMCVSS 5.5fixed in 1.6.402026-07-21
CVE-2026-47390 [MEDIUM] CWE-918 CVE-2026-47390: PraisonAI is a multi-agent teams system. Prior to version 4.6.40 of PraisonAI, corresponding to vers PraisonAI is a multi-agent teams system. Prior to version 4.6.40 of PraisonAI, corresponding to version 1.6.40 of praisonaiagents, `spider_tools` URL validation can be bypassed using alternate loopback host encodings. The tool contains a URL validation function intended to block local or unsafe targets before fetching attacker-controlled URLs. Howev
ghsanvd
CVE-2026-55530P4MEDIUMCVSS 6.1fixed in 1.6.582026-08-25
CVE-2026-55530 [MEDIUM] CWE-862 CVE-2026-55530: PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.58, ast_grep_rewrite lacks the PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.58, ast_grep_rewrite lacks the @require_approval decorator used by sibling mutation tools. With dry_run=False, an agent-controlled call can pass --update-all and a broad path to rewrite matching files without the expected authorization gate. This issue is fixed in version 1.6.58.
ghsanvd
CVE-2026-47395P4MEDIUMCVSS 5.5fixed in 1.6.402026-07-21
CVE-2026-47395 [MEDIUM] CWE-200 CVE-2026-47395: PraisonAI is a multi-agent teams system. Prior to version 4.6.40 of PraisonAI, corresponding to vers PraisonAI is a multi-agent teams system. Prior to version 4.6.40 of PraisonAI, corresponding to version 1.6.40 of praisonaiagents, PraisonAI's direct-prompt CLI automatically expands `@url:` mentions in raw prompt text before agent execution begins. If a prompt contains `@url:`, the CLI calls `MentionsParser.process(...)`. The `@url:` handler then p
ghsanvd
Mervinpraison Praisonaiagents vulnerabilities | cvebase