{"id":"GHSA-5r2q-3wg3-57m2","title":"Duplicate Advisory: PraisonAI: Prompt Injection Defense Bypassed for HIGH-Level Threats","summary":"Duplicate Advisory: PraisonAI: Prompt Injection Defense Bypassed for HIGH-Level Threats","severity":"high","cvss":7.5,"cwe":["CWE-1188"],"vendor":"praisonai","product":"praisonai","ecosystem":"pip","affected":["praisonai <= 4.6.77"],"published":"2026-07-11","updated":"2026-10-07","sourceUpdated":"2026-10-07T20:43:46Z","source":"GHSA","sourceUrl":"https://github.com/advisories/GHSA-5r2q-3wg3-57m2","references":[{"url":"https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-fj8f-m44g-c479"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-61439"},{"url":"https://www.vulncheck.com/advisories/praisonai-before-prompt-injection-defense-bypass"},{"url":"https://github.com/advisories/GHSA-5r2q-3wg3-57m2"}],"tags":["ghsa","pip"],"ingestedAt":"2026-10-07T20:46:46.981Z","slug":"GHSA-5r2q-3wg3-57m2","body":"## Overview\n\n### Duplicate Advisory\nThis advisory has been withdrawn because it is a duplicate of GHSA-fj8f-m44g-c479. This link is maintained to preserve external references.\n\n### Original Description\nPraisonAI versions before 4.6.78 contain a prompt injection defense misconfiguration where the block threshold defaults to CRITICAL severity, allowing HIGH-level threats to pass through unblocked. Attackers can submit single-vector prompt injection attacks such as instruction overrides or financial manipulation that trigger HIGH severity detection but are logged without blocking, enabling system prompt extraction and unauthorized tool invocations.\n\n## Affected packages\n\n- `praisonai <= 4.6.77`\n\n## Remediation\n\nRefer to the advisory for the patched release.","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":41.3,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}