praisonaiagents vulnerabilities
CVEs whose affected-version data names the praisonaiagents package (pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
44 CVEsRSS
CVE-2026-47390Medium· 5.5PraisonAI spider_tools SSRF protection bypass via alternate loopback host encodings
PraisonAI spider_tools SSRF protection bypass via alternate loopback host encodings
CVE-2026-44339High· 8.6PraisonAI has unsafe tool resolution in `ToolExecutionMixin.execute_tool`: undeclared `__main__` callables execute
PraisonAI has unsafe tool resolution in `ToolExecutionMixin.execute_tool`: undeclared `__main__` callables execute
CVE-2026-44335Critical· 9.8PraisonAI has an SSRF bypass
PraisonAI has an SSRF bypass
CVE-2026-41496High· 8.1PraisonAI: SQL Injection via unvalidated `table_prefix` in 9 conversation store backends (incomplete fix for CVE-2026-40315)
PraisonAI: SQL Injection via unvalidated `table_prefix` in 9 conversation store backends (incomplete fix for CVE-2026-40315)
GHSA-x462-jjpc-q4q4High· 8.1PraisonAI: Cross-Origin Agent Execution via Hardcoded Wildcard CORS and Missing Authentication on AGUI Endpoint
PraisonAI: Cross-Origin Agent Execution via Hardcoded Wildcard CORS and Missing Authentication on AGUI Endpoint
CVE-2026-40153High· 7.4PraisonAIAgents: Environment Variable Secret Exfiltration via os.path.expandvars() Bypassing shell=False in Shell Tool
PraisonAIAgents: Environment Variable Secret Exfiltration via os.path.expandvars() Bypassing shell=False in Shell Tool
CVE-2026-40160HighPraisonAIAgents: SSRF via unvalidated URL in `web_crawl` httpx fallback
PraisonAIAgents: SSRF via unvalidated URL in `web_crawl` httpx fallback
CVE-2026-40117Medium· 6.2PraisonAIAgents: Arbitrary File Read via read_skill_file Missing Workspace Boundary and Approval Gate
PraisonAIAgents: Arbitrary File Read via read_skill_file Missing Workspace Boundary and Approval Gate
CVE-2026-40287High· 8.4PraisonAI Vulnerable to RCE via Automatic tools.py Import
PraisonAI Vulnerable to RCE via Automatic tools.py Import
CVE-2026-40150High· 7.7PraisonAIAgents has SSRF and Local File Read via Unvalidated URLs in web_crawl Tool
PraisonAIAgents has SSRF and Local File Read via Unvalidated URLs in web_crawl Tool
CVE-2026-40152Medium· 5.3PraisonAIAgents: Path Traversal via Unvalidated Glob Pattern in list_files Bypasses Workspace Boundary
PraisonAIAgents: Path Traversal via Unvalidated Glob Pattern in list_files Bypasses Workspace Boundary
CVE-2026-56078Medium· 6.5PraisonAI has Memory State Leakage and Path Traversal in MultiAgent Context Handling
PraisonAI has Memory State Leakage and Path Traversal in MultiAgent Context Handling
CVE-2026-34937High· 7.8PraisonAI: Shell Injection in run_python() via Unescaped $() Substitution
PraisonAI: Shell Injection in run_python() via Unescaped $() Substitution
CVE-2026-34954High· 8.6PraisonAI Has SSRF in FileTools.download_file() via Unvalidated URL
PraisonAI Has SSRF in FileTools.download_file() via Unvalidated URL