PraisonAI vulnerabilities
CVEs whose affected-version data names the PraisonAI package (pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
122 CVEsRSS
CVE-2026-47394HighPraisonAI vulnerable to unauthenticated arbitrary file read via MCP workflow.show, workflow.validate, deploy.validate
PraisonAI vulnerable to unauthenticated arbitrary file read via MCP workflow.show, workflow.validate, deploy.validate
CVE-2026-47398High· 8.1PraisonAI: Arbitrary code execution via unguarded `spec.loader.exec_module` in `agents_generator.py` - sibling of CVE-2026-44334
PraisonAI: Arbitrary code execution via unguarded `spec.loader.exec_module` in `agents_generator.py` - sibling of CVE-2026-44334
CVE-2026-47395Medium· 5.5PraisonAI CLI automatically resolves @url mentions in prompt text and can read loopback URLs into model context
PraisonAI CLI automatically resolves @url mentions in prompt text and can read loopback URLs into model context
CVE-2026-47390Medium· 5.5PraisonAI spider_tools SSRF protection bypass via alternate loopback host encodings
PraisonAI spider_tools SSRF protection bypass via alternate loopback host encodings
CVE-2026-44339High· 8.6PraisonAI has unsafe tool resolution in `ToolExecutionMixin.execute_tool`: undeclared `__main__` callables execute
PraisonAI has unsafe tool resolution in `ToolExecutionMixin.execute_tool`: undeclared `__main__` callables execute
CVE-2026-44340High· 7.5PraisonAI's symlink-extraction bypass of `_safe_extractall` writes outside `dest_dir`
PraisonAI's symlink-extraction bypass of `_safe_extractall` writes outside `dest_dir`
CVE-2026-44338High· 7.3PoCPraisonAI ships and generates a legacy API server with authentication disabled by default, allowing unauthenticated workflow execution
PraisonAI ships and generates a legacy API server with authentication disabled by default, allowing unauthenticated workflow execution
CVE-2026-44337Medium· 6.3PraisonAI knowledge-store backends interpolate unvalidated collection names into SQL and CQL queries
PraisonAI knowledge-store backends interpolate unvalidated collection names into SQL and CQL queries
CVE-2026-44334High· 8.4PraisonAI has unauthenticated RCE via `tool_override.py` (CVE-2026-40287 patch bypass)
PraisonAI has unauthenticated RCE via `tool_override.py` (CVE-2026-40287 patch bypass)
CVE-2026-41496High· 8.1PraisonAI: SQL Injection via unvalidated `table_prefix` in 9 conversation store backends (incomplete fix for CVE-2026-40315)
PraisonAI: SQL Injection via unvalidated `table_prefix` in 9 conversation store backends (incomplete fix for CVE-2026-40315)
CVE-2026-40315MediumPraisonAI: SQLiteConversationStore didn't validate table_prefix when constructing SQL queries
PraisonAI: SQLiteConversationStore didn't validate table_prefix when constructing SQL queries
CVE-2026-40116High· 7.5PraisonAI: Unauthenticated WebSocket Endpoint Proxies to Paid OpenAI Realtime API Without Rate Limits
PraisonAI: Unauthenticated WebSocket Endpoint Proxies to Paid OpenAI Realtime API Without Rate Limits
CVE-2026-40151Medium· 5.3PoCPraisonAI: Unauthenticated Information Disclosure of Agent Instructions via /api/agents in AgentOS
PraisonAI: Unauthenticated Information Disclosure of Agent Instructions via /api/agents in AgentOS
CVE-2026-40159Medium· 5.5PraisonAI Vulnerable to Sensitive Environment Variable Exposure via Untrusted MCP Subprocess Execution
PraisonAI Vulnerable to Sensitive Environment Variable Exposure via Untrusted MCP Subprocess Execution
CVE-2026-40287High· 8.4PraisonAI Vulnerable to RCE via Automatic tools.py Import
PraisonAI Vulnerable to RCE via Automatic tools.py Import
CVE-2026-40113High· 8.4PraisonAI Vulnerable to Argument Injection into Cloud Run Environment Variables via Unsanitized Comma in gcloud --set-env-vars
PraisonAI Vulnerable to Argument Injection into Cloud Run Environment Variables via Unsanitized Comma in gcloud --set-env-vars
CVE-2026-40148Medium· 6.5PraisonAI Vulnerable to Decompression Bomb DoS via Recipe Bundle Extraction Without Size Limits
PraisonAI Vulnerable to Decompression Bomb DoS via Recipe Bundle Extraction Without Size Limits
CVE-2026-40112Medium· 5.4PraisonAI Vulnerable to Stored XSS via Unsanitized Agent Output in HTML Rendering (nh3 Not a Required Dependency)
PraisonAI Vulnerable to Stored XSS via Unsanitized Agent Output in HTML Rendering (nh3 Not a Required Dependency)
CVE-2026-40114High· 7.2PraisonAI Vulnerable to Server-Side Request Forgery via Unvalidated webhook_url in Jobs API
PraisonAI Vulnerable to Server-Side Request Forgery via Unvalidated webhook_url in Jobs API
CVE-2026-40149High· 7.9PraisonAI: Unauthenticated Allow-List Manipulation Bypasses Agent Tool Approval Safety Controls
PraisonAI: Unauthenticated Allow-List Manipulation Bypasses Agent Tool Approval Safety Controls
CVE-2026-40158High· 8.6PraisonAI Vulnerable to Code Injection and Protection Mechanism Failure
PraisonAI Vulnerable to Code Injection and Protection Mechanism Failure
CVE-2026-40115Medium· 6.2PraisonAI has Unrestricted Upload Size in WSGI Recipe Registry Server that Enables Memory Exhaustion DoS
PraisonAI has Unrestricted Upload Size in WSGI Recipe Registry Server that Enables Memory Exhaustion DoS
CVE-2026-40156High· 7.8PraisonAI Vulnerable to Implicit Execution of Arbitrary Code via Automatic `tools.py` Loading
PraisonAI Vulnerable to Implicit Execution of Arbitrary Code via Automatic `tools.py` Loading
CVE-2026-56075High· 8.8PraisonAI: Hardcoded `approval_mode="auto"` in Chainlit UI Overrides Administrator Configuration, Enabling Unapproved Shell Command Execu…
PraisonAI: Hardcoded `approval_mode="auto"` in Chainlit UI Overrides Administrator Configuration, Enabling Unapproved Shell Command Execution
CVE-2026-39891High· 8.8PraisonAI has Template Injection in Agent Tool Definitions
PraisonAI has Template Injection in Agent Tool Definitions
CVE-2026-39889High· 7.5PraisonAI Has Unauthenticated SSE Event Stream that Exposes All Agent Activity in A2U Server
PraisonAI Has Unauthenticated SSE Event Stream that Exposes All Agent Activity in A2U Server
CVE-2026-39308High· 7.1PraisonAI recipe registry publish path traversal allows out-of-root file write
PraisonAI recipe registry publish path traversal allows out-of-root file write
CVE-2026-39306High· 7.3PraisonAI recipe registry pull path traversal writes files outside the chosen output directory
PraisonAI recipe registry pull path traversal writes files outside the chosen output directory
CVE-2026-39307High· 8.1PraisonAI Has Arbitrary File Write (Zip Slip) in Templates Extraction
PraisonAI Has Arbitrary File Write (Zip Slip) in Templates Extraction
CVE-2026-34936High· 7.7PraisonAI: SSRF via Unvalidated api_base in passthrough() Fallback
PraisonAI: SSRF via Unvalidated api_base in passthrough() Fallback