PraisonAI has 126 CVEs on record. Disclosures have slowed: 26 in the last 90 days after 80 in the 90 before. The busiest recent month was June 2026 with 53. The median CVSS is 8.1 (high), with 19 rated critical. None have a confirmed exploitation report. The dominant weakness classes are CWE-306 (20) and CWE-22 (14).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 8.1
- Publish → KEV
- —
- Last 90 days
- 26 prev 80
Weakness classes
Products
- praisonai 126
Worst active — by depth score
CVE-2026-56075High· 8.8PraisonAI before 4.5.128 contains an arbitrary shell command execution vulnerability where the UI modules hardcode approval_mode to auto, overriding administrator configuration from PRAISON_APPROVAL_MODE environment variable61CVE-2026-56076High· 8.1PraisonAI before 1.5.128 contains a cross-origin agent execution vulnerability in the AGUI endpoint that allows remote attackers to trigger arbitrary agent execution57GHSA-mhgx-w3w5-2rvcCritical· 10.0Duplicate Advisory: PraisonAI: CodeAgent Executes LLM-Generated Code Without Sandboxing and Leaks All Environment Secrets55CVE-2026-61445Critical· 9.9PraisonAI before 4.6.78 contains arbitrary file write and command execution vulnerabilities in the AICoder component due to missing path validation and command sanitization in LLM tool calls55GHSA-wj29-gm8v-33x8Critical· 9.9Duplicate Advisory: PraisonAI: AICoder Arbitrary File Write and Command Execution via LLM Tool Calls54
PraisonAI vulnerabilities
CVEs affecting PraisonAI, newest first. Open any entry for full detail, references, and exploit status.
126 CVEsRSS
CVE-2026-56836High· 8.2PraisonAI recipe serve Typer command bypasses the non-localhost authentication guard
PraisonAI recipe serve Typer command bypasses the non-localhost authentication guard
CVE-2026-56833High· 7.5PraisonAI Dynamic Context history and terminal tools read files outside configured storage via path traversal
PraisonAI Dynamic Context history and terminal tools read files outside configured storage via path traversal
CVE-2026-56074Medium· 5.5PoCPraisonAI before 1.5.128 caches tool approval decisions by tool name only, not by invocation arguments, allowing subsequent execute_command calls to bypass approval prompts
PraisonAI before 1.5.128 caches tool approval decisions by tool name only, not by invocation arguments, allowing subsequent execute_command calls to bypass approval prompts. Attackers can exploit this by obtaining initial approval for a …
CVE-2026-56075High· 8.8PoCPraisonAI before 4.5.128 contains an arbitrary shell command execution vulnerability where the UI modules hardcode approval_mode to auto, overriding administrator configuration from PRAISON_APPROVAL_MODE environment variable
PraisonAI before 4.5.128 contains an arbitrary shell command execution vulnerability where the UI modules hardcode approval_mode to auto, overriding administrator configuration from PRAISON_APPROVAL_MODE environment variable. Authenticat…
GHSA-8579-rgg5-ph2mHigh· 8.8PraisonAI DiscordApproval accepts unrelated channel messages as dangerous-tool approvals
PraisonAI DiscordApproval accepts unrelated channel messages as dangerous-tool approvals
GHSA-22cj-m4wf-fv2cHigh· 7.5PraisonAI Dynamic Context history and terminal tools read files outside configured storage via path traversal
PraisonAI Dynamic Context history and terminal tools read files outside configured storage via path traversal
GHSA-5qw8-f2g9-ff29High· 8.2PraisonAI recipe serve Typer command bypasses the non-localhost authentication guard
PraisonAI recipe serve Typer command bypasses the non-localhost authentication guard
GHSA-qvpf-j64c-jmhrHigh· 8.3PraisonAI Slack app_mention bypasses configured user/channel authorization
PraisonAI Slack app_mention bypasses configured user/channel authorization
GHSA-j7qx-p75m-wp7gHigh· 7.5PraisonAI dynamic-context artifact tools read arbitrary host files outside artifact storage
PraisonAI dynamic-context artifact tools read arbitrary host files outside artifact storage
GHSA-fc26-m9pf-v56qHigh· 8.6PraisonAI LinearBot processes unsigned webhooks when LINEAR_WEBHOOK_SECRET is missing
PraisonAI LinearBot processes unsigned webhooks when LINEAR_WEBHOOK_SECRET is missing
GHSA-63v4-w882-g4x2High· 8.8PraisonAI: HTTPApproval dashboard renders tool arguments as raw HTML, allowing approval-page XSS to approve dangerous tools
PraisonAI: HTTPApproval dashboard renders tool arguments as raw HTML, allowing approval-page XSS to approve dangerous tools
GHSA-v847-hxxw-3pxgHigh· 7.8PraisonAI recipe.run_stream skips dangerous-tool policy enforcement
PraisonAI recipe.run_stream skips dangerous-tool policy enforcement
GHSA-w6h2-fr4q-xvxvHigh· 8.8PraisonAI: Compute-bridged file tools allow shell command injection
PraisonAI: Compute-bridged file tools allow shell command injection
GHSA-p4pj-vh7h-6cqhHigh· 7.5PraisonAI: Unauthenticated Local File Inclusion via agent_file path in PraisonAI Jobs API
PraisonAI: Unauthenticated Local File Inclusion via agent_file path in PraisonAI Jobs API
GHSA-4869-x4pr-q22xCritical· 9.8PraisonAI: Unauthenticated RCE via Jobs API + Approval Bypass
PraisonAI: Unauthenticated RCE via Jobs API + Approval Bypass
GHSA-j4hj-7hfh-g2f4Critical· 9.8praisonai: recipe serve auth middleware silently disables itself when no secret is set
praisonai: recipe serve auth middleware silently disables itself when no secret is set
GHSA-fq2m-6wqh-x44gCritical· 9.8PraisonAI: Jobs API exposes agent-execution endpoints with no authentication
PraisonAI: Jobs API exposes agent-execution endpoints with no authentication
GHSA-rjvw-7vvw-549vHigh· 7.2PraisonAI: Jobs webhook SSRF protection bypass via DNS rebinding
PraisonAI: Jobs webhook SSRF protection bypass via DNS rebinding
GHSA-892r-p3jq-jp24Critical· 9.8PraisonAI: AgentOS remains unauthenticated after incomplete fix version and allows remote agent invocation
PraisonAI: AgentOS remains unauthenticated after incomplete fix version and allows remote agent invocation
GHSA-x92v-rpx6-p6cwHigh· 8.6PraisonAI: Webhook signature verification skipped (fail-open) when secret unset, allowing forged inbound webhooks (WhatsApp & Linear bots)
PraisonAI: Webhook signature verification skipped (fail-open) when secret unset, allowing forged inbound webhooks (WhatsApp & Linear bots)
GHSA-p75f-6fp4-p57wCritical· 9.8PraisonAI: Missing Authentication for Critical Function and Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in praisonai
PraisonAI: Missing Authentication for Critical Function and Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in praisonai
GHSA-gcq3-mfvh-3x25High· 7.3PraisonAI Code agent tools fail open without a workspace boundary
PraisonAI Code agent tools fail open without a workspace boundary
GHSA-f44v-7qgw-9gh9High· 8.1PraisonAI GitHub template cache path traversal allows outside-cache file write and directory deletion
PraisonAI GitHub template cache path traversal allows outside-cache file write and directory deletion
GHSA-4qq2-2j2x-x62cHigh· 8.2npm PraisonAI MCPSecurity Basic/OAuth authentication policies accept invalid credentials without validation
npm PraisonAI MCPSecurity Basic/OAuth authentication policies accept invalid credentials without validation
GHSA-vmmj-pfw7-fjwpCritical· 9.9npm PraisonAI codeMode sandbox escape via Function constructor
npm PraisonAI codeMode sandbox escape via Function constructor
GHSA-gqmf-56h7-rrpfHigh· 7.6npm PraisonAI SandboxExecutor network-isolated mode does not block non-proxy-aware network clients
npm PraisonAI SandboxExecutor network-isolated mode does not block non-proxy-aware network clients
GHSA-vjv9-7m7j-h833High· 8.8npm PraisonAI SandboxExecutor allowedCommands bypass via shell chaining
npm PraisonAI SandboxExecutor allowedCommands bypass via shell chaining
GHSA-p69m-4f92-2v84Critical· 9.8PraisonAI: Remote Code Execution via Sandbox Escape in `codeMode` Tool
PraisonAI: Remote Code Execution via Sandbox Escape in `codeMode` Tool
GHSA-9752-mhqh-h34fCritical· 9.4npm PraisonAI AgentOS exposes unauthenticated agent listing and invocation
npm PraisonAI AgentOS exposes unauthenticated agent listing and invocation
GHSA-j4f3-55x4-r6q2Critical· 9.8npm PraisonAI MCPServer exposes unauthenticated HTTP tools/call
npm PraisonAI MCPServer exposes unauthenticated HTTP tools/call