VendorsPraisonpraisonaiagentsall versions
Vulnerabilities

Praison Praisonaiagents

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

15CVEs
CVE-2026-34938
PraisonAI: Python Sandbox Escape via str Subclass startswith() Override in execute_code
Published 2026-04-03 · Analyzed
10.0EPSS 0.132
CVE-2026-40288
PraisonAI: Critical RCE via `type: job` workflow YAML
Published 2026-04-14 · Analyzed
9.8EPSS 0.006
CVE-2026-34937
PraisonAI: Shell Injection in run_python() via Unescaped $() Substitution
Published 2026-04-03 · Analyzed
9.8EPSS 0.005
CVE-2026-44335
SSRF bypass in PraisonAI
Published 2026-05-08 · Analyzed
9.8EPSS 0.004
CVE-2026-40111
PraisonAIAgents has an OS Command Injection via shell=True in Memory Hooks Executor (memory/hooks.py)
Published 2026-04-09 · Analyzed
9.3EPSS 0.002
CVE-2026-40289
PraisonAI Browser Server allows unauthenticated WebSocket clients to hijack connected extension sessions
Published 2026-04-14 · Analyzed
9.1EPSS 0.004
CVE-2026-34954
PraisonAI: SSRF in FileTools.download_file() via Unvalidated URL
Published 2026-04-03 · Analyzed
8.6EPSS 0.004
CVE-2026-44339
PraisonAI has unsafe tool resolution in `ToolExecutionMixin.execute_tool`: undeclared `__main__` callables execute
Published 2026-05-08 · Modified
8.6EPSS 0.004
CVE-2026-40287
PraisonAI has RCE via Automatic tools.py Import
Published 2026-04-14 · Analyzed
8.4EPSS 0.002
CVE-2026-41496
PraisonAI: SQL Injection via unvalidated `table_prefix` in 9 conversation store backends (incomplete fix for CVE-2026-40315)
Published 2026-05-08 · Modified
8.1EPSS 0.003
CVE-2026-40150
PraisonAIAgents has SSRF and Local File Read via Unvalidated URLs in web_crawl Tool
Published 2026-04-09 · Analyzed
7.7EPSS 0.003
CVE-2026-40117
PraisonAIAgents Affected by Arbitrary File Read via read_skill_file Missing Workspace Boundary and Approval Gate
Published 2026-04-09 · Analyzed
7.5EPSS 0.002
CVE-2026-40153
PraisonAIAgents Affected by Environment Variable Secret Exfiltration via os.path.expandvars() Bypassing shell=False in Shell Tool
Published 2026-04-09 · Analyzed
7.4EPSS 0.003
CVE-2026-40160
PraisonAIAgents has SSRF via unvalidated URL in `web_crawl` httpx fallback
Published 2026-04-10 · Analyzed
7.1EPSS 0.004
CVE-2026-40152
PraisonAIAgents has a Path Traversal via Unvalidated Glob Pattern in list_files Bypasses Workspace Boundary
Published 2026-04-09 · Analyzed
5.3EPSS 0.003