Newly released CVEs across every platform — sleek to read, verbose on demand, and served raw as markdown for AI and agent ingestion. Severity reads as depth: the deeper the contact, the graver the threat.
Depth = severity + exploitation
CVE-2026-55528High· 8.2praisonaiagents: AgentServer declares auth_token but never enforces it on any route
CVE-2026-55526High· 8.5praisonaiagents has an SSRF protection bypass in `spider_tools._host_is_blocked()` via DNS-resolved hostnames (`127.0.0.1.nip.io`)
CVE-2026-55530Medium· 6.1praisonaiagents: ast_grep_rewrite rewrites arbitrary files without the @require_approval gate enforced on every sibling mutation tool
CVE-2026-55527High· 7.1praisonaiagents vulnerable to arbitrary file write via unsanitized `user_id` in `FileMemory.__init__()` — path traversal to any writable location
CVE-2026-55525High· 7.5praisonaiagents web_crawl vulnerable to SSRF via redirect-following
CVE-2026-55524High· 7.5PraisonAI is a multi-agent teams system. In versions prior to 1.6.58, the web_crawl tool performs its SSRF check only on the initially supplied URL, allowing the protection to be bypassed so the tool connects to attacker-chosen internal …
CVE-2026-55522High· 7.8PraisonAI is a multi-agent teams system. In versions 3.9.26 through 4.6.57 of praiseonai and 0.12.12 through 1.6.57 of praiseonaiagents, the workflow "include" feature is vulnerable to code execution. Workflow._execute_include() implicit…
CVE-2026-55523HighPraisonAI is a multi-agent teams system. In versions 1.5.128 through 1.6.57, the praisonaiagents.tools.web_crawl_tools.web_crawl() function is vulnerable to server-side request forgery. While it validates the initially supplied URL and b…
CVE-2026-56074Medium· 5.5PraisonAI: Coarse-Grained Tool Approval Cache Bypasses Per-Invocation Consent for Shell Commands
CVE-2026-57118Critical· 9.8PraisonAI AgentTeam.launch exposes unauthenticated remote agent listing and invocation endpoints
CVE-2026-57143High· 8.8PraisonAI: Server-Side Request Forgery (SSRF) in SearxNG / search_web tools via attacker-controlled searxng_url parameter
GHSA-35w5-pcw4-jx94Medium· 4.3PraisonAI: Unauthenticated Event Injection via SSE `/publish` Endpoint
GHSA-vmf9-xx9w-86wxHigh· 8.3PraisonAI ToolsMCPServer legacy SSE transport accepts attacker Host/Origin and exposes registered tools
GHSA-6h9p-93hq-q7h6Medium· 6.5PraisonAI: SpiderTools redirect-target SSRF protection bypass
GHSA-pv2j-rghr-v5r9Medium· 6.5PraisonAI: execute_code sandbox bypass: str.format C-level attribute access reads every blocklisted dunder
GHSA-x227-pf99-vffgCritical· 9.8PraisonAI: MCP SSE transport binds 0.0.0.0 with no authentication and no Origin validation; bundled SecurityConfig is never wired in
GHSA-vxgj-xg5c-p4h7High· 8.5praisonaiagents: SSRF guard validates literal IPs only and never resolves DNS
GHSA-2rcg-mm5h-xchxHigh· 7.5PraisonAI: Arbitrary File Read via `@file:` Mention Path Traversal
GHSA-x8cv-xmq7-p8xpCritical· 9.8PraisonAI AgentTeam.launch exposes unauthenticated remote agent listing and invocation endpoints
GHSA-c969-5x3p-vq3vHigh· 8.1PraisonAI: IMAP Command Injection via Unsanitized Email Search Parameters
GHSA-4pcv-mg8v-vrgfHigh· 8.8PraisonAI: Server-Side Request Forgery (SSRF) in SearxNG / search_web tools via attacker-controlled searxng_url parameter
CVE-2026-47395Medium· 5.5PraisonAI CLI automatically resolves @url mentions in prompt text and can read loopback URLs into model context
CVE-2026-47390Medium· 5.5PraisonAI spider_tools SSRF protection bypass via alternate loopback host encodings
CVE-2026-44339High· 8.6PraisonAI has unsafe tool resolution in `ToolExecutionMixin.execute_tool`: undeclared `__main__` callables execute
CVE-2026-44335Critical· 9.8PraisonAI has an SSRF bypass
A summary of everything that shipped over the last two weeks — the whole corpus is open, agents get change feeds, alias resolution and EPSS movers, and the data now includes CVE.org, vendor CSAF, aggregated exploits and per-source scores.
A step-by-step guide to plugging VulnSea into automated and agentic workflows — poll the delta, triage without burning tokens, match an SBOM, and let an MCP-native model do the reasoning.
CVE and 0day intelligence that reads like an instrument — built for analysts and AI agents alike. Here's what it does and where it's going.