PraisonAI vulnerabilities
CVEs whose affected-version data names the PraisonAI package (pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
122 CVEsRSS
CVE-2026-55535Medium· 6.8PraisonAI vulnerable to Server-Side Request Forgery via DNS rebinding bypass in webhook_url validation
PraisonAI vulnerable to Server-Side Request Forgery via DNS rebinding bypass in webhook_url validation
CVE-2026-55541HighPraisonAI: `--api-key` flag on `praisonai serve` is not properly enforced
PraisonAI: `--api-key` flag on `praisonai serve` is not properly enforced
CVE-2026-55539High· 8.6PraisonAI: [Auth Bypass] PraisonAI async Jobs API (`/api/v1/runs`) has no authentication — unauthenticated job execution, result theft, c…
PraisonAI: [Auth Bypass] PraisonAI async Jobs API (`/api/v1/runs`) has no authentication — unauthenticated job execution, result theft, cancel and delete
CVE-2026-55533High· 8.2PraisonAI: Authentication fail-open in Recipe server allows unauthenticated access when API key or JWT auth is configured without a secret
PraisonAI: Authentication fail-open in Recipe server allows unauthenticated access when API key or JWT auth is configured without a secret
CVE-2026-55532High· 7.6PraisonAI: Origin-validation bypass (startswith prefix match) enables unauthenticated cross-site request forgery against the PraisonAI MC…
PraisonAI: Origin-validation bypass (startswith prefix match) enables unauthenticated cross-site request forgery against the PraisonAI MCP HTTP server
CVE-2026-55536Critical· 9.1PraisonAI has a Browser Server WebSocket origin validation bypass via unanchored regex (patch bypass of CVE-2026-40289 / GHSA-8x8f-54wf-v…
PraisonAI has a Browser Server WebSocket origin validation bypass via unanchored regex (patch bypass of CVE-2026-40289 / GHSA-8x8f-54wf-vv92)
CVE-2026-55522High· 7.8PraisonAI is a multi-agent teams system
PraisonAI is a multi-agent teams system. In versions 3.9.26 through 4.6.57 of praiseonai and 0.12.12 through 1.6.57 of praiseonaiagents, the workflow "include" feature is vulnerable to code execution. Workflow._execute_include() implicit…
GHSA-fwh2-95jw-g4j6High· 8.8Duplicate Advisory: PraisonAI has Memory State Leakage and Path Traversal in MultiAgent Context Handling
Duplicate Advisory: PraisonAI has Memory State Leakage and Path Traversal in MultiAgent Context Handling
GHSA-x44p-gg67-52fcMedium· 5.5Duplicate Advisory: PraisonAI: Coarse-Grained Tool Approval Cache Bypasses Per-Invocation Consent for Shell Commands
Duplicate Advisory: PraisonAI: Coarse-Grained Tool Approval Cache Bypasses Per-Invocation Consent for Shell Commands
CVE-2026-57117High· 8.8PraisonAI: Compute-bridged file tools allow shell command injection
PraisonAI: Compute-bridged file tools allow shell command injection
CVE-2026-56838High· 7.8PraisonAI recipe.run_stream skips dangerous-tool policy enforcement
PraisonAI recipe.run_stream skips dangerous-tool policy enforcement
CVE-2026-57114High· 7.2PraisonAI: Jobs webhook SSRF protection bypass via DNS rebinding
PraisonAI: Jobs webhook SSRF protection bypass via DNS rebinding
CVE-2026-56835High· 8.3PraisonAI Slack app_mention bypasses configured user/channel authorization
PraisonAI Slack app_mention bypasses configured user/channel authorization
CVE-2026-57146High· 7.5PraisonAI A2U incomplete authentication fix leaves current serve command unauthenticated by default
PraisonAI A2U incomplete authentication fix leaves current serve command unauthenticated by default
CVE-2026-56834High· 7.5PraisonAI dynamic-context artifact tools read arbitrary host files outside artifact storage
PraisonAI dynamic-context artifact tools read arbitrary host files outside artifact storage
CVE-2026-56837High· 8.6PraisonAI LinearBot processes unsigned webhooks when LINEAR_WEBHOOK_SECRET is missing
PraisonAI LinearBot processes unsigned webhooks when LINEAR_WEBHOOK_SECRET is missing
CVE-2026-57113High· 8.1PraisonAI GitHub template cache path traversal allows outside-cache file write and directory deletion
PraisonAI GitHub template cache path traversal allows outside-cache file write and directory deletion
CVE-2026-57116Critical· 9.8PraisonAI: AgentOS remains unauthenticated after incomplete fix version and allows remote agent invocation
PraisonAI: AgentOS remains unauthenticated after incomplete fix version and allows remote agent invocation
CVE-2026-56832High· 8.8PraisonAI DiscordApproval accepts unrelated channel messages as dangerous-tool approvals
PraisonAI DiscordApproval accepts unrelated channel messages as dangerous-tool approvals
CVE-2026-57142High· 7.8PraisonAI recipe workflow policy can be bypassed by declaring and YAML-approving dangerous tools outside TEMPLATE.yaml
PraisonAI recipe workflow policy can be bypassed by declaring and YAML-approving dangerous tools outside TEMPLATE.yaml
CVE-2026-57144High· 8.8PraisonAI SandlockSandbox falls back to unrestricted subprocess execution when Landlock is unavailable
PraisonAI SandlockSandbox falls back to unrestricted subprocess execution when Landlock is unavailable
CVE-2026-56840High· 8.8PraisonAI: HTTPApproval dashboard renders tool arguments as raw HTML, allowing approval-page XSS to approve dangerous tools
PraisonAI: HTTPApproval dashboard renders tool arguments as raw HTML, allowing approval-page XSS to approve dangerous tools
CVE-2026-56836High· 8.2PraisonAI recipe serve Typer command bypasses the non-localhost authentication guard
PraisonAI recipe serve Typer command bypasses the non-localhost authentication guard
CVE-2026-56833High· 7.5PraisonAI Dynamic Context history and terminal tools read files outside configured storage via path traversal
PraisonAI Dynamic Context history and terminal tools read files outside configured storage via path traversal
GHSA-8579-rgg5-ph2mHigh· 8.8PraisonAI DiscordApproval accepts unrelated channel messages as dangerous-tool approvals
PraisonAI DiscordApproval accepts unrelated channel messages as dangerous-tool approvals
GHSA-22cj-m4wf-fv2cHigh· 7.5PraisonAI Dynamic Context history and terminal tools read files outside configured storage via path traversal
PraisonAI Dynamic Context history and terminal tools read files outside configured storage via path traversal
GHSA-vmf9-xx9w-86wxHigh· 8.3PraisonAI ToolsMCPServer legacy SSE transport accepts attacker Host/Origin and exposes registered tools
PraisonAI ToolsMCPServer legacy SSE transport accepts attacker Host/Origin and exposes registered tools
GHSA-5qw8-f2g9-ff29High· 8.2PraisonAI recipe serve Typer command bypasses the non-localhost authentication guard
PraisonAI recipe serve Typer command bypasses the non-localhost authentication guard
GHSA-qvpf-j64c-jmhrHigh· 8.3PraisonAI Slack app_mention bypasses configured user/channel authorization
PraisonAI Slack app_mention bypasses configured user/channel authorization
GHSA-j7qx-p75m-wp7gHigh· 7.5PraisonAI dynamic-context artifact tools read arbitrary host files outside artifact storage
PraisonAI dynamic-context artifact tools read arbitrary host files outside artifact storage