VulnSea

PraisonAI has 126 CVEs on record. Disclosures have slowed: 26 in the last 90 days after 80 in the 90 before. The busiest recent month was June 2026 with 53. The median CVSS is 8.1 (high), with 19 rated critical. None have a confirmed exploitation report. The dominant weakness classes are CWE-306 (20) and CWE-22 (14).

CVEs per month

Last 12 months, by publish date

111201020304050607080910
Exploited share
0% vs 1% corpus
Median CVSS
8.1
Publish → KEV
—
Last 90 days
26 prev 80

Products

  • praisonai 126
126
Total CVEs
19
Critical
0
CISA KEV
0
Exploited

PraisonAI vulnerabilities

CVEs affecting PraisonAI, newest first. Open any entry for full detail, references, and exploit status.

126 CVEsRSS

CVE-2026-60091High· 7.2
yesterday

PraisonAI: Jobs API is unauthenticated by default and allows attacker-controlled webhook SSRF

PraisonAI: Jobs API is unauthenticated by default and allows attacker-controlled webhook SSRF

▾ Twilightpraisonai · praisonaiEPSS 0.30%via GHSA
CVE-2026-60085High
yesterday

PraisonAI: SecurityPolicy command/path/import restrictions are completely unenforced by the default SubprocessSandbox backend

PraisonAI: SecurityPolicy command/path/import restrictions are completely unenforced by the default SubprocessSandbox backend

▾ Twilightpraisonai · praisonaiEPSS 0.41%via GHSA
CVE-2026-61427High· 7.3
yesterday

PraisonAI: MCP HTTP-stream transport is unauthenticated by default, exposing tool enumeration and an unvalidated tool-call surface

PraisonAI: MCP HTTP-stream transport is unauthenticated by default, exposing tool enumeration and an unvalidated tool-call surface

▾ Twilightpraisonai · praisonaiEPSS 0.39%via GHSA
CVE-2026-61434High· 8.8
yesterday

PraisonAI: Shell command allowlist bypass via find -exec built-in action

PraisonAI: Shell command allowlist bypass via find -exec built-in action

▾ Twilightpraisonai · praisonaiEPSS 0.88%via GHSA
CVE-2026-61435High· 8.2
yesterday

PraisonAI: Call API localhost-only authentication bypass via spoofed Host header

PraisonAI: Call API localhost-only authentication bypass via spoofed Host header

▾ Twilightpraisonai · praisonaiEPSS 0.69%via GHSA
CVE-2026-61433High· 7.8
yesterday

PraisonAI: API deploy code generator embeds unescaped YAML fields into Python source

PraisonAI: API deploy code generator embeds unescaped YAML fields into Python source

▾ Twilightpraisonai · praisonaiEPSS 0.21%via GHSA
CVE-2026-60086Medium· 5.3
yesterday

PraisonAI: Prompt-injection defense blocks only when 3+ detector families fire simultaneously; realistic single-vector injections pass through unblocked

PraisonAI: Prompt-injection defense blocks only when 3+ detector families fire simultaneously; realistic single-vector injections pass through unblocked

▾ Sunlitpraisonai · praisonaiEPSS 0.36%via GHSA
CVE-2026-61431Medium· 5.5
yesterday

PraisonAI: ContextGatherer include resolution permits absolute and traversal reads outside the workspace

PraisonAI: ContextGatherer include resolution permits absolute and traversal reads outside the workspace

▾ Sunlitpraisonai · praisonaiEPSS 0.35%via GHSA
CVE-2026-61436High· 8.6
2d ago

PraisonAI: AgentMail webhook mode accepts forged unsigned message.received events and invokes agents

PraisonAI: AgentMail webhook mode accepts forged unsigned message.received events and invokes agents

▾ Twilightpraisonai · praisonaiEPSS 0.52%via OSV
CVE-2026-55529Medium· 6.9
1mo ago

PraisonAI has an origin validation bypass in MCP HTTP Stream transport that allows browser-mediated unauthenticated tool execution on loc…

PraisonAI has an origin validation bypass in MCP HTTP Stream transport that allows browser-mediated unauthenticated tool execution on local MCP server

▾ Sunlitpraisonai · praisonaiEPSS 0.18%via OSV
CVE-2026-55531Medium· 6.5
1mo ago

PraisonAI MCP HTTP server has unauthenticated unbounded session accumulation (memory exhaustion; session TTL never enforced)

PraisonAI MCP HTTP server has unauthenticated unbounded session accumulation (memory exhaustion; session TTL never enforced)

▾ Sunlitpraisonai · praisonaiEPSS 0.45%via OSV
CVE-2026-55534High· 8.6
1mo ago

PraisonAI serve agents --api-key is ignored, allowing unauthenticated remote agent execution

PraisonAI serve agents --api-key is ignored, allowing unauthenticated remote agent execution

▾ Twilightpraisonai · praisonaiEPSS 0.45%via OSV
CVE-2026-55540High· 7.1
1mo ago

PraisonAI: [Path Traversal] agent tools escape the configured workspace via symlinks

PraisonAI: [Path Traversal] agent tools escape the configured workspace via symlinks

▾ Twilightpraisonai · praisonaiEPSS 0.39%via OSV
CVE-2026-55538High· 7.3
1mo ago

PraisonAI: [Auth Bypass] `praisonai serve agents --api-key` is silently ignored — agent-invocation routes (`POST /agents`, `POST /agents/…

PraisonAI: [Auth Bypass] `praisonai serve agents --api-key` is silently ignored — agent-invocation routes (`POST /agents`, `POST /agents/{agent_name}`) run unauthenticated

▾ Twilightpraisonai · praisonaiEPSS 0.45%via OSV
CVE-2026-55537High· 7.1
1mo ago

PraisonAI: Webhook SSRF via DNS fail-open in `JobSubmitRequest.validate_webhook_url()` — bypass of CVE-2026-40114

PraisonAI: Webhook SSRF via DNS fail-open in `JobSubmitRequest.validate_webhook_url()` — bypass of CVE-2026-40114

▾ Twilightpraisonai · praisonaiEPSS 0.27%via OSV
CVE-2026-55535Medium· 6.8
1mo ago

PraisonAI vulnerable to Server-Side Request Forgery via DNS rebinding bypass in webhook_url validation

PraisonAI vulnerable to Server-Side Request Forgery via DNS rebinding bypass in webhook_url validation

▾ Sunlitpraisonai · praisonaiEPSS 0.34%via OSV
CVE-2026-55541High
1mo ago

PraisonAI: `--api-key` flag on `praisonai serve` is not properly enforced

PraisonAI: `--api-key` flag on `praisonai serve` is not properly enforced

▾ Twilightpraisonai · praisonaiEPSS 0.48%via OSV
CVE-2026-55539High· 8.6
1mo ago

PraisonAI: [Auth Bypass] PraisonAI async Jobs API (`/api/v1/runs`) has no authentication — unauthenticated job execution, result theft, c…

PraisonAI: [Auth Bypass] PraisonAI async Jobs API (`/api/v1/runs`) has no authentication — unauthenticated job execution, result theft, cancel and delete

▾ Twilightpraisonai · praisonaiEPSS 0.57%via OSV
CVE-2026-55533High· 8.2
1mo ago

PraisonAI: Authentication fail-open in Recipe server allows unauthenticated access when API key or JWT auth is configured without a secret

PraisonAI: Authentication fail-open in Recipe server allows unauthenticated access when API key or JWT auth is configured without a secret

▾ Twilightpraisonai · praisonaiEPSS 0.49%via OSV
CVE-2026-55532High· 7.6
1mo ago

PraisonAI: Origin-validation bypass (startswith prefix match) enables unauthenticated cross-site request forgery against the PraisonAI MC…

PraisonAI: Origin-validation bypass (startswith prefix match) enables unauthenticated cross-site request forgery against the PraisonAI MCP HTTP server

▾ Twilightpraisonai · praisonaiEPSS 0.20%via OSV
CVE-2026-55536Critical· 9.1
1mo ago

PraisonAI has a Browser Server WebSocket origin validation bypass via unanchored regex (patch bypass of CVE-2026-40289 / GHSA-8x8f-54wf-v…

PraisonAI has a Browser Server WebSocket origin validation bypass via unanchored regex (patch bypass of CVE-2026-40289 / GHSA-8x8f-54wf-vv92)

▾ Midnightpraisonai · praisonaiEPSS 0.52%via OSV
GHSA-65c8-r727-2mpjHigh· 7.5
2mo ago

Duplicate Advisory: PraisonAI: SecurityPolicy command/path/import restrictions are completely unenforced by the default SubprocessSandbox backend

Duplicate Advisory: PraisonAI: SecurityPolicy command/path/import restrictions are completely unenforced by the default SubprocessSandbox backend

▾ TwilightPraisonAI · PraisonAIvia GHSA
GHSA-5866-9272-qcfvMedium· 7.3
2mo ago

Duplicate Advisory: PraisonAI: MCP HTTP-stream transport is unauthenticated by default, exposing tool enumeration and an unvalidated tool-call surface

Duplicate Advisory: PraisonAI: MCP HTTP-stream transport is unauthenticated by default, exposing tool enumeration and an unvalidated tool-call surface

▾ Sunlitpraisonai · praisonaivia GHSA
GHSA-qpq9-hwx9-cwgcHigh· 7.8
2mo ago

Duplicate Advisory: PraisonAI: API deploy code generator embeds unescaped YAML fields into Python source

Duplicate Advisory: PraisonAI: API deploy code generator embeds unescaped YAML fields into Python source

▾ Twilightpraisonai · praisonaivia GHSA
GHSA-gp65-m7q3-4vjwHigh· 8.2
2mo ago

Duplicate Advisory: PraisonAI: Call API localhost-only authentication bypass via spoofed Host header

Duplicate Advisory: PraisonAI: Call API localhost-only authentication bypass via spoofed Host header

▾ Twilightpraisonai · praisonaivia GHSA
GHSA-m64w-vfg6-36phHigh· 8.6
2mo ago

Duplicate Advisory: PraisonAI: AgentMail webhook mode accepts forged unsigned message.received events and invokes agents

Duplicate Advisory: PraisonAI: AgentMail webhook mode accepts forged unsigned message.received events and invokes agents

▾ Twilightpraisonai · praisonaivia GHSA
GHSA-wj29-gm8v-33x8Critical· 9.9
3mo ago

Duplicate Advisory: PraisonAI: AICoder Arbitrary File Write and Command Execution via LLM Tool Calls

Duplicate Advisory: PraisonAI: AICoder Arbitrary File Write and Command Execution via LLM Tool Calls

▾ Midnightpraisonai · praisonaivia GHSA
GHSA-g3pq-3vvx-36w6High· 8.6
3mo ago

Duplicate Advisory: PraisonAI: AgentOS defaults to network-exposed no-auth mode, allowing unauthenticated agent invocation and instruction disclosure

Duplicate Advisory: PraisonAI: AgentOS defaults to network-exposed no-auth mode, allowing unauthenticated agent invocation and instruction disclosure

▾ Twilightpraisonai · praisonaivia GHSA
GHSA-wgvq-3jxh-4qg7Medium· 5.5
3mo ago

Duplicate Advisory: PraisonAI: Project custom command templates can read outside-workspace files into model prompts

Duplicate Advisory: PraisonAI: Project custom command templates can read outside-workspace files into model prompts

▾ Sunlitpraisonai · praisonaivia GHSA
GHSA-q65p-7p84-495cCritical· 9.8
3mo ago

Duplicate Advisory: PraisonAI: PGVector and Cassandra knowledge stores interpolate vector dimensions into DDL

Duplicate Advisory: PraisonAI: PGVector and Cassandra knowledge stores interpolate vector dimensions into DDL

▾ Midnightpraisonai · praisonaivia GHSA
PraisonAI vulnerabilities (CVEs) · VulnSea