PraisonAI has 126 CVEs on record. Disclosures have slowed: 26 in the last 90 days after 80 in the 90 before. The busiest recent month was June 2026 with 53. The median CVSS is 8.1 (high), with 19 rated critical. None have a confirmed exploitation report. The dominant weakness classes are CWE-306 (20) and CWE-22 (14).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 8.1
- Publish → KEV
- —
- Last 90 days
- 26 prev 80
Weakness classes
Products
- praisonai 126
Worst active — by depth score
CVE-2026-56075High· 8.8PraisonAI before 4.5.128 contains an arbitrary shell command execution vulnerability where the UI modules hardcode approval_mode to auto, overriding administrator configuration from PRAISON_APPROVAL_MODE environment variable61CVE-2026-56076High· 8.1PraisonAI before 1.5.128 contains a cross-origin agent execution vulnerability in the AGUI endpoint that allows remote attackers to trigger arbitrary agent execution57GHSA-mhgx-w3w5-2rvcCritical· 10.0Duplicate Advisory: PraisonAI: CodeAgent Executes LLM-Generated Code Without Sandboxing and Leaks All Environment Secrets55CVE-2026-61445Critical· 9.9PraisonAI before 4.6.78 contains arbitrary file write and command execution vulnerabilities in the AICoder component due to missing path validation and command sanitization in LLM tool calls55GHSA-wj29-gm8v-33x8Critical· 9.9Duplicate Advisory: PraisonAI: AICoder Arbitrary File Write and Command Execution via LLM Tool Calls54
PraisonAI vulnerabilities
CVEs affecting PraisonAI, newest first. Open any entry for full detail, references, and exploit status.
126 CVEsRSS
CVE-2026-60091High· 7.2PraisonAI: Jobs API is unauthenticated by default and allows attacker-controlled webhook SSRF
PraisonAI: Jobs API is unauthenticated by default and allows attacker-controlled webhook SSRF
CVE-2026-60085HighPraisonAI: SecurityPolicy command/path/import restrictions are completely unenforced by the default SubprocessSandbox backend
PraisonAI: SecurityPolicy command/path/import restrictions are completely unenforced by the default SubprocessSandbox backend
CVE-2026-61427High· 7.3PraisonAI: MCP HTTP-stream transport is unauthenticated by default, exposing tool enumeration and an unvalidated tool-call surface
PraisonAI: MCP HTTP-stream transport is unauthenticated by default, exposing tool enumeration and an unvalidated tool-call surface
CVE-2026-61434High· 8.8PraisonAI: Shell command allowlist bypass via find -exec built-in action
PraisonAI: Shell command allowlist bypass via find -exec built-in action
CVE-2026-61435High· 8.2PraisonAI: Call API localhost-only authentication bypass via spoofed Host header
PraisonAI: Call API localhost-only authentication bypass via spoofed Host header
CVE-2026-61433High· 7.8PraisonAI: API deploy code generator embeds unescaped YAML fields into Python source
PraisonAI: API deploy code generator embeds unescaped YAML fields into Python source
CVE-2026-60086Medium· 5.3PraisonAI: Prompt-injection defense blocks only when 3+ detector families fire simultaneously; realistic single-vector injections pass through unblocked
PraisonAI: Prompt-injection defense blocks only when 3+ detector families fire simultaneously; realistic single-vector injections pass through unblocked
CVE-2026-61431Medium· 5.5PraisonAI: ContextGatherer include resolution permits absolute and traversal reads outside the workspace
PraisonAI: ContextGatherer include resolution permits absolute and traversal reads outside the workspace
CVE-2026-61436High· 8.6PraisonAI: AgentMail webhook mode accepts forged unsigned message.received events and invokes agents
PraisonAI: AgentMail webhook mode accepts forged unsigned message.received events and invokes agents
CVE-2026-55529Medium· 6.9PraisonAI has an origin validation bypass in MCP HTTP Stream transport that allows browser-mediated unauthenticated tool execution on loc…
PraisonAI has an origin validation bypass in MCP HTTP Stream transport that allows browser-mediated unauthenticated tool execution on local MCP server
CVE-2026-55531Medium· 6.5PraisonAI MCP HTTP server has unauthenticated unbounded session accumulation (memory exhaustion; session TTL never enforced)
PraisonAI MCP HTTP server has unauthenticated unbounded session accumulation (memory exhaustion; session TTL never enforced)
CVE-2026-55534High· 8.6PraisonAI serve agents --api-key is ignored, allowing unauthenticated remote agent execution
PraisonAI serve agents --api-key is ignored, allowing unauthenticated remote agent execution
CVE-2026-55540High· 7.1PraisonAI: [Path Traversal] agent tools escape the configured workspace via symlinks
PraisonAI: [Path Traversal] agent tools escape the configured workspace via symlinks
CVE-2026-55538High· 7.3PraisonAI: [Auth Bypass] `praisonai serve agents --api-key` is silently ignored — agent-invocation routes (`POST /agents`, `POST /agents/…
PraisonAI: [Auth Bypass] `praisonai serve agents --api-key` is silently ignored — agent-invocation routes (`POST /agents`, `POST /agents/{agent_name}`) run unauthenticated
CVE-2026-55537High· 7.1PraisonAI: Webhook SSRF via DNS fail-open in `JobSubmitRequest.validate_webhook_url()` — bypass of CVE-2026-40114
PraisonAI: Webhook SSRF via DNS fail-open in `JobSubmitRequest.validate_webhook_url()` — bypass of CVE-2026-40114
CVE-2026-55535Medium· 6.8PraisonAI vulnerable to Server-Side Request Forgery via DNS rebinding bypass in webhook_url validation
PraisonAI vulnerable to Server-Side Request Forgery via DNS rebinding bypass in webhook_url validation
CVE-2026-55541HighPraisonAI: `--api-key` flag on `praisonai serve` is not properly enforced
PraisonAI: `--api-key` flag on `praisonai serve` is not properly enforced
CVE-2026-55539High· 8.6PraisonAI: [Auth Bypass] PraisonAI async Jobs API (`/api/v1/runs`) has no authentication — unauthenticated job execution, result theft, c…
PraisonAI: [Auth Bypass] PraisonAI async Jobs API (`/api/v1/runs`) has no authentication — unauthenticated job execution, result theft, cancel and delete
CVE-2026-55533High· 8.2PraisonAI: Authentication fail-open in Recipe server allows unauthenticated access when API key or JWT auth is configured without a secret
PraisonAI: Authentication fail-open in Recipe server allows unauthenticated access when API key or JWT auth is configured without a secret
CVE-2026-55532High· 7.6PraisonAI: Origin-validation bypass (startswith prefix match) enables unauthenticated cross-site request forgery against the PraisonAI MC…
PraisonAI: Origin-validation bypass (startswith prefix match) enables unauthenticated cross-site request forgery against the PraisonAI MCP HTTP server
CVE-2026-55536Critical· 9.1PraisonAI has a Browser Server WebSocket origin validation bypass via unanchored regex (patch bypass of CVE-2026-40289 / GHSA-8x8f-54wf-v…
PraisonAI has a Browser Server WebSocket origin validation bypass via unanchored regex (patch bypass of CVE-2026-40289 / GHSA-8x8f-54wf-vv92)
GHSA-65c8-r727-2mpjHigh· 7.5Duplicate Advisory: PraisonAI: SecurityPolicy command/path/import restrictions are completely unenforced by the default SubprocessSandbox backend
Duplicate Advisory: PraisonAI: SecurityPolicy command/path/import restrictions are completely unenforced by the default SubprocessSandbox backend
GHSA-5866-9272-qcfvMedium· 7.3Duplicate Advisory: PraisonAI: MCP HTTP-stream transport is unauthenticated by default, exposing tool enumeration and an unvalidated tool-call surface
Duplicate Advisory: PraisonAI: MCP HTTP-stream transport is unauthenticated by default, exposing tool enumeration and an unvalidated tool-call surface
GHSA-qpq9-hwx9-cwgcHigh· 7.8Duplicate Advisory: PraisonAI: API deploy code generator embeds unescaped YAML fields into Python source
Duplicate Advisory: PraisonAI: API deploy code generator embeds unescaped YAML fields into Python source
GHSA-gp65-m7q3-4vjwHigh· 8.2Duplicate Advisory: PraisonAI: Call API localhost-only authentication bypass via spoofed Host header
Duplicate Advisory: PraisonAI: Call API localhost-only authentication bypass via spoofed Host header
GHSA-m64w-vfg6-36phHigh· 8.6Duplicate Advisory: PraisonAI: AgentMail webhook mode accepts forged unsigned message.received events and invokes agents
Duplicate Advisory: PraisonAI: AgentMail webhook mode accepts forged unsigned message.received events and invokes agents
GHSA-wj29-gm8v-33x8Critical· 9.9Duplicate Advisory: PraisonAI: AICoder Arbitrary File Write and Command Execution via LLM Tool Calls
Duplicate Advisory: PraisonAI: AICoder Arbitrary File Write and Command Execution via LLM Tool Calls
GHSA-g3pq-3vvx-36w6High· 8.6Duplicate Advisory: PraisonAI: AgentOS defaults to network-exposed no-auth mode, allowing unauthenticated agent invocation and instruction disclosure
Duplicate Advisory: PraisonAI: AgentOS defaults to network-exposed no-auth mode, allowing unauthenticated agent invocation and instruction disclosure
GHSA-wgvq-3jxh-4qg7Medium· 5.5Duplicate Advisory: PraisonAI: Project custom command templates can read outside-workspace files into model prompts
Duplicate Advisory: PraisonAI: Project custom command templates can read outside-workspace files into model prompts
GHSA-q65p-7p84-495cCritical· 9.8Duplicate Advisory: PraisonAI: PGVector and Cassandra knowledge stores interpolate vector dimensions into DDL
Duplicate Advisory: PraisonAI: PGVector and Cassandra knowledge stores interpolate vector dimensions into DDL