GHSA-5r2q-3wg3-57m2High· 7.5▾ TwilightDuplicate Advisory: PraisonAI: Prompt Injection Defense Bypassed for HIGH-Level Threats
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via GHSA
Last analysed / modified upstream
This advisory has been withdrawn because it is a duplicate of GHSA-fj8f-m44g-c479. This link is maintained to preserve external references.
PraisonAI versions before 4.6.78 contain a prompt injection defense misconfiguration where the block threshold defaults to CRITICAL severity, allowing HIGH-level threats to pass through unblocked. Attackers can submit single-vector prompt injection attacks such as instruction overrides or financial manipulation that trigger HIGH severity detection but are logged without blocking, enabling system prompt extraction and unauthorized tool invocations.
praisonai <= 4.6.77Refer to the advisory for the patched release.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-61439High· 7.5PraisonAI versions before 4.6.78 contain a prompt injection defense misconfiguration where the block threshold defaults to CRITICAL severity, allowing HIGH-level threats to pass through unblocked
CVE-2026-57127Critical· 9.8PraisonAI is a multi-agent teams system
CVE-2026-57148Critical· 9.8PraisonAI is a multi-agent teams system
CVE-2026-57147Critical· 9.8PraisonAI is a multi-agent teams system
GHSA-j4hj-7hfh-g2f4Critical· 9.8praisonai: recipe serve auth middleware silently disables itself when no secret is set
CVE-2026-57139Critical· 9.8PraisonAI is a multi-agent teams system