PraisonAI has 126 CVEs on record. Disclosures have slowed: 26 in the last 90 days after 80 in the 90 before. The busiest recent month was June 2026 with 53. The median CVSS is 8.1 (high), with 19 rated critical. None have a confirmed exploitation report. The dominant weakness classes are CWE-306 (20) and CWE-22 (14).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 8.1
- Publish → KEV
- —
- Last 90 days
- 26 prev 80
Weakness classes
Products
- praisonai 126
Worst active — by depth score
CVE-2026-56075High· 8.8PraisonAI before 4.5.128 contains an arbitrary shell command execution vulnerability where the UI modules hardcode approval_mode to auto, overriding administrator configuration from PRAISON_APPROVAL_MODE environment variable61CVE-2026-56076High· 8.1PraisonAI before 1.5.128 contains a cross-origin agent execution vulnerability in the AGUI endpoint that allows remote attackers to trigger arbitrary agent execution57GHSA-mhgx-w3w5-2rvcCritical· 10.0Duplicate Advisory: PraisonAI: CodeAgent Executes LLM-Generated Code Without Sandboxing and Leaks All Environment Secrets55CVE-2026-61445Critical· 9.9PraisonAI before 4.6.78 contains arbitrary file write and command execution vulnerabilities in the AICoder component due to missing path validation and command sanitization in LLM tool calls55GHSA-wj29-gm8v-33x8Critical· 9.9Duplicate Advisory: PraisonAI: AICoder Arbitrary File Write and Command Execution via LLM Tool Calls54
PraisonAI vulnerabilities
CVEs affecting PraisonAI, newest first. Open any entry for full detail, references, and exploit status.
126 CVEsRSS
GHSA-mhgx-w3w5-2rvcCritical· 10.0Duplicate Advisory: PraisonAI: CodeAgent Executes LLM-Generated Code Without Sandboxing and Leaks All Environment Secrets
Duplicate Advisory: PraisonAI: CodeAgent Executes LLM-Generated Code Without Sandboxing and Leaks All Environment Secrets
GHSA-5r2q-3wg3-57m2High· 7.5Duplicate Advisory: PraisonAI: Prompt Injection Defense Bypassed for HIGH-Level Threats
Duplicate Advisory: PraisonAI: Prompt Injection Defense Bypassed for HIGH-Level Threats
GHSA-4mp6-8448-9vgvMedium· 7.3Duplicate Advisory: PraisonAI: AgentMail webhook lacks signature verification, allowing unauthenticated message injection and sender spoofing
Duplicate Advisory: PraisonAI: AgentMail webhook lacks signature verification, allowing unauthenticated message injection and sender spoofing
CVE-2026-61445Critical· 9.9PraisonAI before 4.6.78 contains arbitrary file write and command execution vulnerabilities in the AICoder component due to missing path validation and command sanitization in LLM tool calls
PraisonAI before 4.6.78 contains arbitrary file write and command execution vulnerabilities in the AICoder component due to missing path validation and command sanitization in LLM tool calls. Attackers can inject malicious prompts throug…
CVE-2026-61439High· 7.5PraisonAI versions before 4.6.78 contain a prompt injection defense misconfiguration where the block threshold defaults to CRITICAL severity, allowing HIGH-level threats to pass through unblocked
PraisonAI versions before 4.6.78 contain a prompt injection defense misconfiguration where the block threshold defaults to CRITICAL severity, allowing HIGH-level threats to pass through unblocked. Attackers can submit single-vector promp…
CVE-2026-61428High· 7.3PraisonAI AgentMail versions before 4.6.78 lack signature verification in webhook mode, allowing unauthenticated attackers to inject messages with spoofed sender addresses
PraisonAI AgentMail versions before 4.6.78 lack signature verification in webhook mode, allowing unauthenticated attackers to inject messages with spoofed sender addresses. Attackers can POST crafted message.received events to the webhoo…
CVE-2026-61426High· 8.6PraisonAI before 1.7.3 contains an insecure default configuration that binds to all interfaces with no API key requirement and wildcard CORS
PraisonAI before 1.7.3 contains an insecure default configuration that binds to all interfaces with no API key requirement and wildcard CORS. Unauthenticated attackers can call GET /api/agents to read agent instructions and system prompt…
CVE-2026-60090Critical· 9.8PraisonAI before 4.6.78 fails to validate the caller-controlled dimension argument in the PGVector and Cassandra knowledge-store create_collection() backends
PraisonAI before 4.6.78 fails to validate the caller-controlled dimension argument in the PGVector and Cassandra knowledge-store create_collection() backends. Although schema, keyspace, and collection-name identifiers are validated, the …
CVE-2026-60088Medium· 5.5PraisonAI before 4.6.78 fails to validate file path references in custom command templates, allowing attackers to read files outside the workspace
PraisonAI before 4.6.78 fails to validate file path references in custom command templates, allowing attackers to read files outside the workspace. Attackers can include path traversal sequences like @../outside_secret.txt or absolute pa…
GHSA-3wrm-pm5v-8vq8Medium· 7.2Duplicate Advisory: PraisonAI: Jobs API is unauthenticated by default and allows attacker-controlled webhook SSRF
Duplicate Advisory: PraisonAI: Jobs API is unauthenticated by default and allows attacker-controlled webhook SSRF
GHSA-wrw8-384c-cg76High· 8.8Duplicate Advisory: PraisonAI: Shell command allowlist bypass via find -exec built-in action
Duplicate Advisory: PraisonAI: Shell command allowlist bypass via find -exec built-in action
GHSA-5c3v-h6hw-4gx7Medium· 5.3Duplicate Advisory: PraisonAI: Prompt-injection defense blocks only when 3+ detector families fire simultaneously; realistic single-vector injections pass through unblocked
Duplicate Advisory: PraisonAI: Prompt-injection defense blocks only when 3+ detector families fire simultaneously; realistic single-vector injections pass through unblocked
GHSA-w37c-cq55-frjpMedium· 5.5Duplicate Advisory: PraisonAI: ContextGatherer include resolution permits absolute and traversal reads outside the workspace
Duplicate Advisory: PraisonAI: ContextGatherer include resolution permits absolute and traversal reads outside the workspace
CVE-2026-61444Critical· 9.1PraisonAI versions before 4.6.78 contain a code injection vulnerability in deploy/api.py where the agents_file parameter is directly interpolated into an f-string without sanitization
PraisonAI versions before 4.6.78 contain a code injection vulnerability in deploy/api.py where the agents_file parameter is directly interpolated into an f-string without sanitization. Attackers can inject arbitrary Python code that exec…
GHSA-fwh2-95jw-g4j6High· 8.8Duplicate Advisory: PraisonAI has Memory State Leakage and Path Traversal in MultiAgent Context Handling
Duplicate Advisory: PraisonAI has Memory State Leakage and Path Traversal in MultiAgent Context Handling
GHSA-x44p-gg67-52fcMedium· 5.5Duplicate Advisory: PraisonAI: Coarse-Grained Tool Approval Cache Bypasses Per-Invocation Consent for Shell Commands
Duplicate Advisory: PraisonAI: Coarse-Grained Tool Approval Cache Bypasses Per-Invocation Consent for Shell Commands
CVE-2026-56076High· 8.1PoCPraisonAI before 1.5.128 contains a cross-origin agent execution vulnerability in the AGUI endpoint that allows remote attackers to trigger arbitrary agent execution
PraisonAI before 1.5.128 contains a cross-origin agent execution vulnerability in the AGUI endpoint that allows remote attackers to trigger arbitrary agent execution. The POST /agui endpoint lacks authentication and hardcodes Access-Cont…
CVE-2026-57117High· 8.8PraisonAI: Compute-bridged file tools allow shell command injection
PraisonAI: Compute-bridged file tools allow shell command injection
CVE-2026-56838High· 7.8PraisonAI recipe.run_stream skips dangerous-tool policy enforcement
PraisonAI recipe.run_stream skips dangerous-tool policy enforcement
CVE-2026-57114High· 7.2PraisonAI: Jobs webhook SSRF protection bypass via DNS rebinding
PraisonAI: Jobs webhook SSRF protection bypass via DNS rebinding
CVE-2026-56835High· 8.3PraisonAI Slack app_mention bypasses configured user/channel authorization
PraisonAI Slack app_mention bypasses configured user/channel authorization
CVE-2026-57146High· 7.5PraisonAI A2U incomplete authentication fix leaves current serve command unauthenticated by default
PraisonAI A2U incomplete authentication fix leaves current serve command unauthenticated by default
CVE-2026-56834High· 7.5PraisonAI dynamic-context artifact tools read arbitrary host files outside artifact storage
PraisonAI dynamic-context artifact tools read arbitrary host files outside artifact storage
CVE-2026-56837High· 8.6PraisonAI LinearBot processes unsigned webhooks when LINEAR_WEBHOOK_SECRET is missing
PraisonAI LinearBot processes unsigned webhooks when LINEAR_WEBHOOK_SECRET is missing
CVE-2026-57113High· 8.1PraisonAI GitHub template cache path traversal allows outside-cache file write and directory deletion
PraisonAI GitHub template cache path traversal allows outside-cache file write and directory deletion
CVE-2026-57116Critical· 9.8PraisonAI: AgentOS remains unauthenticated after incomplete fix version and allows remote agent invocation
PraisonAI: AgentOS remains unauthenticated after incomplete fix version and allows remote agent invocation
CVE-2026-56832High· 8.8PraisonAI DiscordApproval accepts unrelated channel messages as dangerous-tool approvals
PraisonAI DiscordApproval accepts unrelated channel messages as dangerous-tool approvals
CVE-2026-57142High· 7.8PraisonAI recipe workflow policy can be bypassed by declaring and YAML-approving dangerous tools outside TEMPLATE.yaml
PraisonAI recipe workflow policy can be bypassed by declaring and YAML-approving dangerous tools outside TEMPLATE.yaml
CVE-2026-57144High· 8.8PraisonAI SandlockSandbox falls back to unrestricted subprocess execution when Landlock is unavailable
PraisonAI SandlockSandbox falls back to unrestricted subprocess execution when Landlock is unavailable
CVE-2026-56840High· 8.8PraisonAI: HTTPApproval dashboard renders tool arguments as raw HTML, allowing approval-page XSS to approve dangerous tools
PraisonAI: HTTPApproval dashboard renders tool arguments as raw HTML, allowing approval-page XSS to approve dangerous tools