VulnSea

PraisonAI has 126 CVEs on record. Disclosures have slowed: 26 in the last 90 days after 80 in the 90 before. The busiest recent month was June 2026 with 53. The median CVSS is 8.1 (high), with 19 rated critical. None have a confirmed exploitation report. The dominant weakness classes are CWE-306 (20) and CWE-22 (14).

CVEs per month

Last 12 months, by publish date

111201020304050607080910
Exploited share
0% vs 1% corpus
Median CVSS
8.1
Publish → KEV
—
Last 90 days
26 prev 80

Products

  • praisonai 126
126
Total CVEs
19
Critical
0
CISA KEV
0
Exploited

PraisonAI vulnerabilities

CVEs affecting PraisonAI, newest first. Open any entry for full detail, references, and exploit status.

126 CVEsRSS

GHSA-mhgx-w3w5-2rvcCritical· 10.0
3mo ago

Duplicate Advisory: PraisonAI: CodeAgent Executes LLM-Generated Code Without Sandboxing and Leaks All Environment Secrets

Duplicate Advisory: PraisonAI: CodeAgent Executes LLM-Generated Code Without Sandboxing and Leaks All Environment Secrets

▾ Midnightpraisonai · praisonaivia GHSA
GHSA-5r2q-3wg3-57m2High· 7.5
3mo ago

Duplicate Advisory: PraisonAI: Prompt Injection Defense Bypassed for HIGH-Level Threats

Duplicate Advisory: PraisonAI: Prompt Injection Defense Bypassed for HIGH-Level Threats

▾ Twilightpraisonai · praisonaivia GHSA
GHSA-4mp6-8448-9vgvMedium· 7.3
3mo ago

Duplicate Advisory: PraisonAI: AgentMail webhook lacks signature verification, allowing unauthenticated message injection and sender spoofing

Duplicate Advisory: PraisonAI: AgentMail webhook lacks signature verification, allowing unauthenticated message injection and sender spoofing

▾ Sunlitpraisonai · praisonaivia GHSA
CVE-2026-61445Critical· 9.9
3mo ago

PraisonAI before 4.6.78 contains arbitrary file write and command execution vulnerabilities in the AICoder component due to missing path validation and command sanitization in LLM tool calls

PraisonAI before 4.6.78 contains arbitrary file write and command execution vulnerabilities in the AICoder component due to missing path validation and command sanitization in LLM tool calls. Attackers can inject malicious prompts throug…

▾ Midnightpraisonai · praisonaiEPSS 0.88%via NVD
CVE-2026-61439High· 7.5
3mo ago

PraisonAI versions before 4.6.78 contain a prompt injection defense misconfiguration where the block threshold defaults to CRITICAL severity, allowing HIGH-level threats to pass through unblocked

PraisonAI versions before 4.6.78 contain a prompt injection defense misconfiguration where the block threshold defaults to CRITICAL severity, allowing HIGH-level threats to pass through unblocked. Attackers can submit single-vector promp…

▾ TwilightPraisonAI · PraisonAIEPSS 0.43%via NVD
CVE-2026-61428High· 7.3
3mo ago

PraisonAI AgentMail versions before 4.6.78 lack signature verification in webhook mode, allowing unauthenticated attackers to inject messages with spoofed sender addresses

PraisonAI AgentMail versions before 4.6.78 lack signature verification in webhook mode, allowing unauthenticated attackers to inject messages with spoofed sender addresses. Attackers can POST crafted message.received events to the webhoo…

▾ Twilightpraisonai · praisonaiEPSS 0.37%via NVD
CVE-2026-61426High· 8.6
3mo ago

PraisonAI before 1.7.3 contains an insecure default configuration that binds to all interfaces with no API key requirement and wildcard CORS

PraisonAI before 1.7.3 contains an insecure default configuration that binds to all interfaces with no API key requirement and wildcard CORS. Unauthenticated attackers can call GET /api/agents to read agent instructions and system prompt…

▾ Twilightpraisonai · praisonaiEPSS 0.48%via NVD
CVE-2026-60090Critical· 9.8
3mo ago

PraisonAI before 4.6.78 fails to validate the caller-controlled dimension argument in the PGVector and Cassandra knowledge-store create_collection() backends

PraisonAI before 4.6.78 fails to validate the caller-controlled dimension argument in the PGVector and Cassandra knowledge-store create_collection() backends. Although schema, keyspace, and collection-name identifiers are validated, the …

▾ Midnightpraisonai · praisonaiEPSS 0.70%via NVD
CVE-2026-60088Medium· 5.5
3mo ago

PraisonAI before 4.6.78 fails to validate file path references in custom command templates, allowing attackers to read files outside the workspace

PraisonAI before 4.6.78 fails to validate file path references in custom command templates, allowing attackers to read files outside the workspace. Attackers can include path traversal sequences like @../outside_secret.txt or absolute pa…

▾ Sunlitpraisonai · praisonaiEPSS 0.18%via NVD
GHSA-3wrm-pm5v-8vq8Medium· 7.2
3mo ago

Duplicate Advisory: PraisonAI: Jobs API is unauthenticated by default and allows attacker-controlled webhook SSRF

Duplicate Advisory: PraisonAI: Jobs API is unauthenticated by default and allows attacker-controlled webhook SSRF

▾ Sunlitpraisonai · praisonaivia GHSA
GHSA-wrw8-384c-cg76High· 8.8
3mo ago

Duplicate Advisory: PraisonAI: Shell command allowlist bypass via find -exec built-in action

Duplicate Advisory: PraisonAI: Shell command allowlist bypass via find -exec built-in action

▾ TwilightPraisonAI · PraisonAIvia GHSA
GHSA-5c3v-h6hw-4gx7Medium· 5.3
3mo ago

Duplicate Advisory: PraisonAI: Prompt-injection defense blocks only when 3+ detector families fire simultaneously; realistic single-vector injections pass through unblocked

Duplicate Advisory: PraisonAI: Prompt-injection defense blocks only when 3+ detector families fire simultaneously; realistic single-vector injections pass through unblocked

▾ Sunlitpraisonai · praisonaivia GHSA
GHSA-w37c-cq55-frjpMedium· 5.5
3mo ago

Duplicate Advisory: PraisonAI: ContextGatherer include resolution permits absolute and traversal reads outside the workspace

Duplicate Advisory: PraisonAI: ContextGatherer include resolution permits absolute and traversal reads outside the workspace

▾ Sunlitpraisonai · praisonaivia GHSA
CVE-2026-61444Critical· 9.1
3mo ago

PraisonAI versions before 4.6.78 contain a code injection vulnerability in deploy/api.py where the agents_file parameter is directly interpolated into an f-string without sanitization

PraisonAI versions before 4.6.78 contain a code injection vulnerability in deploy/api.py where the agents_file parameter is directly interpolated into an f-string without sanitization. Attackers can inject arbitrary Python code that exec…

▾ Midnightpraisonai · praisonaiEPSS 0.57%via NVD
GHSA-fwh2-95jw-g4j6High· 8.8
3mo ago

Duplicate Advisory: PraisonAI has Memory State Leakage and Path Traversal in MultiAgent Context Handling

Duplicate Advisory: PraisonAI has Memory State Leakage and Path Traversal in MultiAgent Context Handling

▾ Twilightpraisonai · praisonaivia GHSA
GHSA-x44p-gg67-52fcMedium· 5.5
3mo ago

Duplicate Advisory: PraisonAI: Coarse-Grained Tool Approval Cache Bypasses Per-Invocation Consent for Shell Commands

Duplicate Advisory: PraisonAI: Coarse-Grained Tool Approval Cache Bypasses Per-Invocation Consent for Shell Commands

▾ Sunlitpraisonai · praisonaivia GHSA
CVE-2026-56076High· 8.1PoC
3mo ago

PraisonAI before 1.5.128 contains a cross-origin agent execution vulnerability in the AGUI endpoint that allows remote attackers to trigger arbitrary agent execution

PraisonAI before 1.5.128 contains a cross-origin agent execution vulnerability in the AGUI endpoint that allows remote attackers to trigger arbitrary agent execution. The POST /agui endpoint lacks authentication and hardcodes Access-Cont…

▾ MidnightPraisonAI · PraisonAIEPSS 0.74%via NVD
CVE-2026-57117High· 8.8
3mo ago

PraisonAI: Compute-bridged file tools allow shell command injection

PraisonAI: Compute-bridged file tools allow shell command injection

▾ Twilightpraisonai · praisonaivia OSV
CVE-2026-56838High· 7.8
3mo ago

PraisonAI recipe.run_stream skips dangerous-tool policy enforcement

PraisonAI recipe.run_stream skips dangerous-tool policy enforcement

▾ Twilightpraisonai · praisonaivia OSV
CVE-2026-57114High· 7.2
3mo ago

PraisonAI: Jobs webhook SSRF protection bypass via DNS rebinding

PraisonAI: Jobs webhook SSRF protection bypass via DNS rebinding

▾ Twilightpraisonai · praisonaivia OSV
CVE-2026-56835High· 8.3
3mo ago

PraisonAI Slack app_mention bypasses configured user/channel authorization

PraisonAI Slack app_mention bypasses configured user/channel authorization

▾ Twilightpraisonai · praisonaivia OSV
CVE-2026-57146High· 7.5
3mo ago

PraisonAI A2U incomplete authentication fix leaves current serve command unauthenticated by default

PraisonAI A2U incomplete authentication fix leaves current serve command unauthenticated by default

▾ Twilightpraisonai · praisonaivia OSV
CVE-2026-56834High· 7.5
3mo ago

PraisonAI dynamic-context artifact tools read arbitrary host files outside artifact storage

PraisonAI dynamic-context artifact tools read arbitrary host files outside artifact storage

▾ Twilightpraisonai · praisonaivia OSV
CVE-2026-56837High· 8.6
3mo ago

PraisonAI LinearBot processes unsigned webhooks when LINEAR_WEBHOOK_SECRET is missing

PraisonAI LinearBot processes unsigned webhooks when LINEAR_WEBHOOK_SECRET is missing

▾ Twilightpraisonai · praisonaivia OSV
CVE-2026-57113High· 8.1
3mo ago

PraisonAI GitHub template cache path traversal allows outside-cache file write and directory deletion

PraisonAI GitHub template cache path traversal allows outside-cache file write and directory deletion

▾ Twilightpraisonai · praisonaivia OSV
CVE-2026-57116Critical· 9.8
3mo ago

PraisonAI: AgentOS remains unauthenticated after incomplete fix version and allows remote agent invocation

PraisonAI: AgentOS remains unauthenticated after incomplete fix version and allows remote agent invocation

▾ Midnightpraisonai · praisonaivia OSV
CVE-2026-56832High· 8.8
3mo ago

PraisonAI DiscordApproval accepts unrelated channel messages as dangerous-tool approvals

PraisonAI DiscordApproval accepts unrelated channel messages as dangerous-tool approvals

▾ Twilightpraisonai · praisonaivia OSV
CVE-2026-57142High· 7.8
3mo ago

PraisonAI recipe workflow policy can be bypassed by declaring and YAML-approving dangerous tools outside TEMPLATE.yaml

PraisonAI recipe workflow policy can be bypassed by declaring and YAML-approving dangerous tools outside TEMPLATE.yaml

▾ Twilightpraisonai · praisonaivia OSV
CVE-2026-57144High· 8.8
3mo ago

PraisonAI SandlockSandbox falls back to unrestricted subprocess execution when Landlock is unavailable

PraisonAI SandlockSandbox falls back to unrestricted subprocess execution when Landlock is unavailable

▾ Twilightpraisonai · praisonaivia OSV
CVE-2026-56840High· 8.8
3mo ago

PraisonAI: HTTPApproval dashboard renders tool arguments as raw HTML, allowing approval-page XSS to approve dangerous tools

PraisonAI: HTTPApproval dashboard renders tool arguments as raw HTML, allowing approval-page XSS to approve dangerous tools

▾ Twilightpraisonai · praisonaivia OSV
PraisonAI vulnerabilities (CVEs) — page 2 · VulnSea