Praison Praisonaiagents vulnerabilities
15 known vulnerabilities affecting praison/praisonaiagents.
Total CVEs
15
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL5HIGH6MEDIUM4
Vulnerabilities
Page 1 of 1
CVE-2026-40288P2CRITICALCVSS 9.8fixed in 1.5.1402026-04-14
CVE-2026-40288 [CRITICAL] CWE-78 CVE-2026-40288: PraisonAI is a multi-agent teams system. In versions below 4.5.139 of PraisonAI and 1.5.140 of prais
PraisonAI is a multi-agent teams system. In versions below 4.5.139 of PraisonAI and 1.5.140 of praisonaiagents, the workflow engine is vulnerable to arbitrary command and code execution through untrusted YAML files. When praisonai workflow run loads a YAML file with type: job, the JobWorkflowExecutor in job_workflow.py processes steps that support
nvd
CVE-2026-34938P2CRITICALCVSS 10.0fixed in 1.5.902026-04-03
CVE-2026-34938 [CRITICAL] CWE-693 CVE-2026-34938: PraisonAI is a multi-agent teams system. Prior to version 1.5.90, execute_code() in praisonai-agents
PraisonAI is a multi-agent teams system. Prior to version 1.5.90, execute_code() in praisonai-agents runs attacker-controlled Python inside a three-layer sandbox that can be fully bypassed by passing a str subclass with an overridden startswith() method to the _safe_getattr wrapper, achieving arbitrary OS command execution on the host. This issue
nvd
CVE-2026-40289P2CRITICALCVSS 9.1fixed in 1.5.1402026-04-14
CVE-2026-40289 [CRITICAL] CWE-306 CVE-2026-40289: PraisonAI is a multi-agent teams system. In versions below 4.5.139 of PraisonAI and 1.5.140 of prais
PraisonAI is a multi-agent teams system. In versions below 4.5.139 of PraisonAI and 1.5.140 of praisonaiagents, the browser bridge (praisonai browser start) is vulnerable to unauthenticated remote session hijacking due to missing authentication and a bypassable origin check on its /ws WebSocket endpoint. The server binds to 0.0.0.0 by default and
nvd
CVE-2026-34937P2CRITICALCVSS 9.8fixed in 1.5.902026-04-03
CVE-2026-34937 [CRITICAL] CWE-78 CVE-2026-34937: PraisonAI is a multi-agent teams system. Prior to version 1.5.90, run_python() in praisonai construc
PraisonAI is a multi-agent teams system. Prior to version 1.5.90, run_python() in praisonai constructs a shell command string by interpolating user-controlled code into python3 -c "" and passing it to subprocess.run(..., shell=True). The escaping logic only handles \ and ", leaving $() and backtick substitutions unescaped, allowing arbitrary OS com
nvd
CVE-2026-44335P3CRITICALCVSS 9.8fixed in 1.6.322026-05-08
CVE-2026-44335 [CRITICAL] CWE-918 CVE-2026-44335: PraisonAI is a multi-agent teams system. Prior to version 1.6.32, the URL checking logic in PraisonA
PraisonAI is a multi-agent teams system. Prior to version 1.6.32, the URL checking logic in PraisonAI has a logical flaw that could be bypassed by attackers, leading to SSRF attacks. This issue has been patched in version 1.6.32.
nvd
CVE-2026-34954P3HIGHCVSS 8.6fixed in 1.5.952026-04-03
CVE-2026-34954 [HIGH] CWE-918 CVE-2026-34954: PraisonAI is a multi-agent teams system. Prior to version 1.5.95, FileTools.download_file() in prais
PraisonAI is a multi-agent teams system. Prior to version 1.5.95, FileTools.download_file() in praisonaiagents validates the destination path but performs no validation on the url parameter, passing it directly to httpx.stream() with follow_redirects=True. An attacker who controls the URL can reach any host accessible from the server including cloud m
nvd
CVE-2026-40111P3HIGHCVSS 8.8fixed in 1.5.1282026-04-09
CVE-2026-40111 [HIGH] CWE-78 CVE-2026-40111: PraisonAIAgents is a multi-agent teams system. Prior to 1.5.128, he memory hooks executor in praison
PraisonAIAgents is a multi-agent teams system. Prior to 1.5.128, he memory hooks executor in praisonaiagents passes a user-controlled command string directly to subprocess.run() with shell=True at src/praisonai-agents/praisonaiagents/memory/hooks.py. No sanitization is performed and shell metacharacters are interpreted by /bin/sh before the intended co
nvd
CVE-2026-41496P3HIGHCVSS 8.1fixed in 1.6.92026-05-08
CVE-2026-41496 [HIGH] CVE-2026-41496: PraisonAI is a multi-agent teams system. Prior to praisonai version 4.6.9 and praisonaiagents versio
PraisonAI is a multi-agent teams system. Prior to praisonai version 4.6.9 and praisonaiagents version 1.6.9, the fix for CVE-2026-40315 added input validation to SQLiteConversationStore only. Nine sibling backends — MySQL, PostgreSQL, async SQLite/MySQL/PostgreSQL, Turso, SingleStore, Supabase, SurrealDB — pass table_prefix straight into f-string SQL. Same ro
nvd
CVE-2026-44339P3HIGHCVSS 8.6fixed in 1.6.372026-05-08
CVE-2026-44339 [HIGH] CWE-470 CVE-2026-44339: PraisonAI is a multi-agent teams system. Prior to praisonai version 4.6.37 and praisonaiagents versi
PraisonAI is a multi-agent teams system. Prior to praisonai version 4.6.37 and praisonaiagents version 1.6.37, praisonaiagents resolves unresolved tool names against module globals and __main__ after it fails to match the declared tool list and the registry. With the default agent configuration, _perm_allow is None, so undeclared non-dangerous tool na
nvd
CVE-2026-40287P3HIGHCVSS 8.4fixed in 1.5.1402026-04-14
CVE-2026-40287 [HIGH] CWE-94 CVE-2026-40287: PraisonAI is a multi-agent teams system. Versions 4.5.138 and below are vulnerable to arbitrary code
PraisonAI is a multi-agent teams system. Versions 4.5.138 and below are vulnerable to arbitrary code execution through automatic, unsanitized import of a tools.py file from the current working directory. Components including call.py (import_tools_from_file()), tool_resolver.py (_load_local_tools()), and CLI tool-loading paths blindly import ./tools.py
nvd
CVE-2026-40117P3HIGHCVSS 7.5fixed in 1.5.1282026-04-09
CVE-2026-40117 [HIGH] CWE-862 CVE-2026-40117: PraisonAIAgents is a multi-agent teams system. Prior to 1.5.128, read_skill_file() in skill_tools.py
PraisonAIAgents is a multi-agent teams system. Prior to 1.5.128, read_skill_file() in skill_tools.py allows reading arbitrary files from the filesystem by accepting an unrestricted skill_path parameter. Unlike file_tools.read_file which enforces workspace boundary confinement, and unlike run_skill_script which requires critical-level approval, read_sk
nvd
CVE-2026-40150P3MEDIUMCVSS 6.5fixed in 1.5.1282026-04-09
CVE-2026-40150 [MEDIUM] CWE-918 CVE-2026-40150: PraisonAIAgents is a multi-agent teams system. Prior to 1.5.128, the web_crawl() function in praison
PraisonAIAgents is a multi-agent teams system. Prior to 1.5.128, the web_crawl() function in praisonaiagents/tools/web_crawl_tools.py accepts arbitrary URLs from AI agents with zero validation. No scheme allowlisting, hostname/IP blocklisting, or private network checks are applied before fetching. This allows an attacker (or prompt injection in craw
nvd
CVE-2026-40153P3MEDIUMCVSS 6.5fixed in 1.5.1282026-04-09
CVE-2026-40153 [MEDIUM] CWE-526 CVE-2026-40153: PraisonAIAgents is a multi-agent teams system. Prior to 1.5.128, the execute_command function in she
PraisonAIAgents is a multi-agent teams system. Prior to 1.5.128, the execute_command function in shell_tools.py calls os.path.expandvars() on every command argument at line 64, manually re-implementing shell-level environment variable expansion despite using shell=False (line 88) for security. This allows exfiltration of secrets stored in environmen
nvd
CVE-2026-40160P3MEDIUMCVSS 6.5fixed in 1.5.1282026-04-10
CVE-2026-40160 [MEDIUM] CWE-918 CVE-2026-40160: PraisonAIAgents is a multi-agent teams system. Prior to 1.5.128, web_crawl's httpx fallback path pas
PraisonAIAgents is a multi-agent teams system. Prior to 1.5.128, web_crawl's httpx fallback path passes user-supplied URLs directly to httpx.AsyncClient.get() with follow_redirects=True and no host validation. An LLM agent tricked into crawling an internal URL can reach cloud metadata endpoints (169.254.169.254), internal services, and localhost. Th
nvd
CVE-2026-40152P3MEDIUMCVSS 5.3fixed in 1.5.1282026-04-09
CVE-2026-40152 [MEDIUM] CWE-22 CVE-2026-40152: PraisonAIAgents is a multi-agent teams system. Prior to 1.5.128, he list_files() tool in FileTools v
PraisonAIAgents is a multi-agent teams system. Prior to 1.5.128, he list_files() tool in FileTools validates the directory parameter against workspace boundaries via _validate_path(), but passes the pattern parameter directly to Path.glob() without any validation. Since Python's Path.glob() supports .. path segments, an attacker can use relative path
nvd