VYPR

Vendor CVEs

Praison

All CVEs

117 total · sorted by risk
  • CVE-2026-40151MedApr 9, 2026
    risk 0.28cvss 5.3epss 0.01

    PraisonAI is a multi-agent teams system. Prior to 4.5.128, the AgentOS deployment platform exposes a GET /api/agents endpoint that returns agent names, roles, and the first 100 characters of agent system instructions to any unauthenticated caller. The AgentOS FastAPI application…

  • CVE-2026-40112MedApr 9, 2026
    risk 0.28cvss 5.4epss 0.00

    PraisonAI is a multi-agent teams system. Prior to 4.5.128, the Flask API endpoint in src/praisonai/api.py renders agent output as HTML without effective sanitization. The _sanitize_html function relies on the nh3 library, which is not listed as a required or optional dependency…

  • CVE-2026-57120medJun 18, 2026
    risk 0.26cvss epss

    ## Summary The `execute_code` tool's subprocess sandbox advertises a three-layer defense (AST validation, text-pattern blocklist, restricted `__builtins__`). In **sandbox mode** (the default) only two layers are active — the text-pattern blocklist is skipped — and both…

  • CVE-2026-57128medJun 18, 2026
    risk 0.26cvss epss

    ## Summary The SSE (Server-Sent Events) server in `src/praisonai-agents/praisonaiagents/server/server.py` exposes a `/publish` endpoint that broadcasts arbitrary messages to all connected clients without any authentication. The `ServerConfig` dataclass (line 24) defines an…

  • CVE-2026-48168CriAug 5, 2026
    risk 0.00cvss 10.0epss 0.01

    PraisonAI is a multi-agent teams system. In versions prior to 4.6.40, the bundled Claude GitHub Actions workflow is vulnerable to command injection because it embeds an attacker-controlled pull request branch name into a Bash run: block without quoting or validation.…

  • CVE-2026-61443HigJul 15, 2026
    risk 0.00cvss 8.1epss 0.01

    PraisonAI before 1.6.78 contains a remote code execution vulnerability in SkillTools.run_skill_script() that executes scripts without path containment validation. Attackers can supply absolute file paths to execute arbitrary scripts from any filesystem location, including those…

  • CVE-2026-61440MedJul 15, 2026
    risk 0.00cvss 6.5epss 0.00

    PraisonAI Platform before 0.1.9 fails to properly authorize label and issue-label mutations, allowing workspace members to rename and recolor shared labels and add or remove labels on owner-created issues. Attackers with workspace member privileges can exploit PATCH and…

  • CVE-2026-61438HigJul 15, 2026
    risk 0.00cvss 7.3epss 0.00

    PraisonAI before 4.6.78 contains a remote code execution vulnerability in JobWorkflowExecutor._exec_inline_python() due to insufficient AST validation of workflow script steps. Attackers can create malicious YAML workflow files with import os statements followed by os.system()…

  • CVE-2026-61436HigJul 15, 2026
    risk 0.00cvss 8.6epss 0.00

    PraisonAI before 4.6.78 fails to verify Svix webhook signatures in AgentMail webhook mode, allowing unauthenticated attackers to forge message.received events. Attackers can send crafted JSON payloads to the webhook endpoint to invoke configured agents with arbitrary sender…

  • CVE-2026-61447CriJul 11, 2026
    risk 0.00cvss 10.0epss 0.02

    PraisonAI before 1.6.78 contains a remote code execution vulnerability in CodeAgent._execute_python() that executes LLM-generated Python code without AST validation, import restrictions, or sandbox enforcement. Attackers can influence LLM output through prompt injection to…

  • CVE-2026-61445CriJul 11, 2026
    risk 0.00cvss 9.9epss 0.01

    PraisonAI before 4.6.78 contains arbitrary file write and command execution vulnerabilities in the AICoder component due to missing path validation and command sanitization in LLM tool calls. Attackers can inject malicious prompts through the chat interface to write files to…

  • CVE-2026-61442HigJul 11, 2026
    risk 0.00cvss 7.1epss 0.00

    PraisonAI Platform (praisonai-platform) before 0.1.9 fails to enforce owner/admin authorization on the PATCH routes for projects, issues, and agents, which only require workspace-member role. A workspace member can modify owner-created records; for projects, a member can…

  • CVE-2026-61439HigJul 11, 2026
    risk 0.00cvss 7.5epss 0.00

    PraisonAI versions before 4.6.78 contain a prompt injection defense misconfiguration where the block threshold defaults to CRITICAL severity, allowing HIGH-level threats to pass through unblocked. Attackers can submit single-vector prompt injection attacks such as instruction…

  • CVE-2026-60088MedJul 11, 2026
    risk 0.00cvss 5.5epss 0.00

    PraisonAI before 4.6.78 fails to validate file path references in custom command templates, allowing attackers to read files outside the workspace. Attackers can include path traversal sequences like @../outside_secret.txt or absolute paths in project command files to exfiltrate…

  • CVE-2026-61441MedJul 10, 2026
    risk 0.00cvss 6.5epss 0.00

    PraisonAI Platform (praisonai-platform) before 0.1.9 improperly authorizes deletion of issue dependencies. The DELETE dependency route accepts either endpoint of a dependency edge and checks delete permission only against the caller-selected URL issue. A workspace member who…

  • CVE-2026-61432MedJul 10, 2026
    risk 0.00cvss 5.7epss 0.00

    PraisonAI (praisonaiagents) before 1.6.78 contains a path traversal vulnerability in the FastContext feature (praisonaiagents.context.fast). FastContextAgent.execute_tool() prepends the configured workspace_path only for relative paths and neither rejects absolute paths nor…

  • CVE-2026-60086MedJul 10, 2026
    risk 0.00cvss 5.3epss 0.00

    PraisonAI before 4.6.78 contains a prompt injection defense bypass vulnerability where the injection defense only blocks threats classified as CRITICAL, requiring three or more detector families to match simultaneously. Attackers can craft single or double-vector prompt…

Page 3 of 3