GHSA-5c3v-h6hw-4gx7Medium· 5.3▾ SunlitDuplicate Advisory: PraisonAI: Prompt-injection defense blocks only when 3+ detector families fire simultaneously; realistic single-vector injections pass through unblocked
▾ Sunlit zone — Low / medium · no exploitation signal
impact 29.2 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via GHSA
Last analysed / modified upstream
This advisory has been withdrawn because it is a duplicate of GHSA-4r3p-w3mc-5v34. This link is maintained to preserve external references.
PraisonAI before 4.6.78 contains a prompt injection defense bypass vulnerability where the injection defense only blocks threats classified as CRITICAL, requiring three or more detector families to match simultaneously. Attackers can craft single or double-vector prompt injections that are classified as HIGH threat level and pass through unblocked to reach the model.
praisonai <= 4.6.77Refer to the advisory for the patched release.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-60086Medium· 5.3PraisonAI: Prompt-injection defense blocks only when 3+ detector families fire simultaneously; realistic single-vector injections pass through unblocked
CVE-2026-61439High· 7.5PraisonAI versions before 4.6.78 contain a prompt injection defense misconfiguration where the block threshold defaults to CRITICAL severity, allowing HIGH-level threats to pass through unblocked
CVE-2026-61434High· 8.8PraisonAI: Shell command allowlist bypass via find -exec built-in action
GHSA-5r2q-3wg3-57m2High· 7.5Duplicate Advisory: PraisonAI: Prompt Injection Defense Bypassed for HIGH-Level Threats
GHSA-v847-hxxw-3pxgHigh· 7.8PraisonAI recipe.run_stream skips dangerous-tool policy enforcement
GHSA-6jcq-6546-qrrwHigh· 8.8PraisonAI SandlockSandbox falls back to unrestricted subprocess execution when Landlock is unavailable