VendorsPraisonpraisonaiall versions
Vulnerabilities

Praison Praisonai

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

43CVEs
CVE-2026-39305
Arbitrary File Write / Path Traversal in Action Orchestrator
Published 2026-04-07 · Analyzed
10.0EPSS 0.004
CVE-2026-34955
PraisonAI: Sandbox Escape via shell=True and Bypassable Blocklist in SubprocessSandbox
Published 2026-04-03 · Analyzed
10.0EPSS 0.004
CVE-2026-40114
PraisonAI has Server-Side Request Forgery via Unvalidated webhook_url in Jobs API
Published 2026-04-09 · Analyzed
10.0EPSS 0.003
CVE-2026-39888
PraisonAIAgents has a sandbox escape via exception frame traversal in `execute_code` (subprocess mode)
Published 2026-04-08 · Analyzed
9.9EPSS 0.006
CVE-2026-34935
PraisonAI: OS Command Injection in MCPHandler.parse_mcp_command()
Published 2026-04-03 · Analyzed
9.8EPSS 0.010
CVE-2026-40288
PraisonAI: Critical RCE via `type: job` workflow YAML
Published 2026-04-14 · Analyzed
9.8EPSS 0.009
CVE-2026-39890
PraisonAI Affected by Remote Code Execution via YAML Deserialization in Agent Definition Loading
Published 2026-04-08 · Analyzed
9.8EPSS 0.008
CVE-2026-41497
Incomplete fix for CVE-2026-34935: Command Injection in MervinPraison/PraisonAI
Published 2026-05-08 · Analyzed
9.8EPSS 0.008
CVE-2026-34934
PraisonAI: Second-Order SQL Injection in `get_all_user_threads`
Published 2026-04-03 · Analyzed
9.8EPSS 0.006
CVE-2026-40315
PraisonAI: SQLiteConversationStore didn't validate table_prefix when constructing SQL queries
Published 2026-04-14 · Analyzed
9.8EPSS 0.004
CVE-2026-44336
PraisonAI MCP `tools/call` path-traversal and RCE via Python `.pth` injection
Published 2026-05-08 · Modified
9.6EPSS 0.007
CVE-2026-40088
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in praisonai
Published 2026-04-09 · Analyzed
9.6EPSS 0.006
CVE-2026-40154
PraisonAI Affected by Untrusted Remote Template Code Execution
Published 2026-04-09 · Analyzed
9.6EPSS 0.005
CVE-2026-40157
PraisonAI affected by arbitrary file write via path traversal in `praisonai recipe unpack`
Published 2026-04-10 · Analyzed
9.4EPSS 0.005
CVE-2026-35615
PraisonAI has a Path Traversal in FileTools
Published 2026-04-07 · Analyzed
9.2EPSS 0.005
CVE-2026-40289
PraisonAI Browser Server allows unauthenticated WebSocket clients to hijack connected extension sessions
Published 2026-04-14 · Analyzed
9.1EPSS 0.005
CVE-2026-34952
PraisonAI: Missing Authentication in WebSocket Gateway
Published 2026-04-03 · Analyzed
9.1EPSS 0.005
CVE-2026-40313
PraisonAI: ArtiPACKED Vulnerability via GitHub Actions Credential Persistence
Published 2026-04-14 · Analyzed
9.1EPSS 0.005
CVE-2026-34953
PraisonAI: Authentication Bypass in OAuthManager.validate_token()
Published 2026-04-03 · Analyzed
9.1EPSS 0.004
CVE-2026-39891
PraisonAI has a Template Injection in Agent Tool Definitions
Published 2026-04-08 · Analyzed
8.8EPSS 0.006
CVE-2026-44340
PraisonAI: Symlink-extraction bypass of `_safe_extractall` writes outside `dest_dir`
Published 2026-05-08 · Analyzed
8.7EPSS 0.005
CVE-2026-44339
PraisonAI has unsafe tool resolution in `ToolExecutionMixin.execute_tool`: undeclared `__main__` callables execute
Published 2026-05-08 · Modified
8.6EPSS 0.004
CVE-2026-40158
PraisonAI has Improper Control of Generation of Code ('Code Injection') and Protection Mechanism Failure in praisonai
Published 2026-04-10 · Analyzed
8.6EPSS 0.002
CVE-2026-40113
PraisonAI has an Argument Injection into Cloud Run Environment Variables via Unsanitized Comma in gcloud --set-env-vars
Published 2026-04-09 · Analyzed
8.4EPSS 0.003
CVE-2026-44334
PraisonAI: Unauthenticated RCE via `tool_override.py`
Published 2026-05-08 · Analyzed
8.4EPSS 0.002
CVE-2026-40287
PraisonAI has RCE via Automatic tools.py Import
Published 2026-04-14 · Analyzed
8.4EPSS 0.002
CVE-2026-39307
PraisonAI has an Arbitrary File Write (Zip Slip) in Templates Extraction
Published 2026-04-07 · Analyzed
8.1EPSS 0.005
CVE-2026-41496
PraisonAI: SQL Injection via unvalidated `table_prefix` in 9 conversation store backends (incomplete fix for CVE-2026-40315)
Published 2026-05-08 · Modified
8.1EPSS 0.004
CVE-2026-40149
PraisonAI has an Unauthenticated Allow-List Manipulation Bypasses Agent Tool Approval Safety Controls
Published 2026-04-09 · Analyzed
7.9EPSS 0.002
CVE-2026-40156
PraisonAI Affected by Implicit Execution of Arbitrary Code via Automatic `tools.py` Loading
Published 2026-04-10 · Analyzed
7.8EPSS 0.002
CVE-2026-34936
PraisonAI: SSRF via Unvalidated api_base in passthrough() Fallback
Published 2026-04-03 · Analyzed
7.7EPSS 0.004
CVE-2026-40116
PraisonAI's Unauthenticated WebSocket Endpoint Proxies to Paid OpenAI Realtime API Without Rate Limits
Published 2026-04-09 · Analyzed
7.5EPSS 0.006
CVE-2026-39889
PraisonAI has Unauthenticated SSE Event Stream Exposes All Agent Activity in A2U Server
Published 2026-04-08 · Analyzed
7.5EPSS 0.005
CVE-2026-34939
PraisonAI: ReDoS via Unvalidated User-Controlled Regex in MCPToolIndex.search_tools()
Published 2026-04-03 · Analyzed
7.5EPSS 0.004
CVE-2026-40115
PraisonAI has an Unrestricted Upload Size in WSGI Recipe Registry Server Enables Memory Exhaustion DoS
Published 2026-04-09 · Analyzed
7.5EPSS 0.004
CVE-2026-44338
PraisonAI ships and generates a legacy API server with authentication disabled by default, allowing unauthenticated workflow execution
Published 2026-05-08 · Analyzed
7.3EPSS 0.008
CVE-2026-39306
PraisonAI recipe registry pull path traversal writes files outside the chosen output directory
Published 2026-04-07 · Analyzed
7.3EPSS 0.004
CVE-2026-39308
PraisonAI recipe registry publish path traversal allows out-of-root file write
Published 2026-04-07 · Analyzed
7.1EPSS 0.005
CVE-2026-40148
PraisonAI Affected by Decompression Bomb DoS via Recipe Bundle Extraction Without Size Limits
Published 2026-04-09 · Analyzed
6.5EPSS 0.004
CVE-2026-44337
PraisonAI knowledge-store backends interpolate unvalidated collection names into SQL and CQL queries
Published 2026-05-08 · Analyzed
6.3EPSS 0.003
1 / 2Next →