PraisonAI has 126 CVEs on record. Disclosures have slowed: 26 in the last 90 days after 80 in the 90 before. The busiest recent month was June 2026 with 53. The median CVSS is 8.1 (high), with 19 rated critical. None have a confirmed exploitation report. The dominant weakness classes are CWE-306 (20) and CWE-22 (14).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 8.1
- Publish → KEV
- —
- Last 90 days
- 26 prev 80
Weakness classes
Products
- praisonai 126
Worst active — by depth score
CVE-2026-56075High· 8.8PraisonAI before 4.5.128 contains an arbitrary shell command execution vulnerability where the UI modules hardcode approval_mode to auto, overriding administrator configuration from PRAISON_APPROVAL_MODE environment variable61CVE-2026-56076High· 8.1PraisonAI before 1.5.128 contains a cross-origin agent execution vulnerability in the AGUI endpoint that allows remote attackers to trigger arbitrary agent execution57GHSA-mhgx-w3w5-2rvcCritical· 10.0Duplicate Advisory: PraisonAI: CodeAgent Executes LLM-Generated Code Without Sandboxing and Leaks All Environment Secrets55CVE-2026-61445Critical· 9.9PraisonAI before 4.6.78 contains arbitrary file write and command execution vulnerabilities in the AICoder component due to missing path validation and command sanitization in LLM tool calls55GHSA-wj29-gm8v-33x8Critical· 9.9Duplicate Advisory: PraisonAI: AICoder Arbitrary File Write and Command Execution via LLM Tool Calls54
PraisonAI vulnerabilities
CVEs affecting PraisonAI, newest first. Open any entry for full detail, references, and exploit status.
126 CVEsRSS
GHSA-h2w2-v7j6-xqm4High· 8.8npm PraisonAI AgentLoop onToolCall approval runs after tool execution
npm PraisonAI AgentLoop onToolCall approval runs after tool execution
GHSA-5jv7-2mjm-h6qjHigh· 8.8npm PraisonAI utility shell safe-command wrapper allowlist bypass via shell chaining
npm PraisonAI utility shell safe-command wrapper allowlist bypass via shell chaining
GHSA-7qw2-w5rc-37x2High· 7.8PraisonAI recipe workflow policy can be bypassed by declaring and YAML-approving dangerous tools outside TEMPLATE.yaml
PraisonAI recipe workflow policy can be bypassed by declaring and YAML-approving dangerous tools outside TEMPLATE.yaml
GHSA-jxcw-qp4h-6jfqHigh· 7.5PraisonAI A2U incomplete authentication fix leaves current serve command unauthenticated by default
PraisonAI A2U incomplete authentication fix leaves current serve command unauthenticated by default
GHSA-29w3-p9w9-wc47Critical· 9.1PraisonAI: Arbitrary File Read/Write via `multiedit` Tool Without Path Validation
PraisonAI: Arbitrary File Read/Write via `multiedit` Tool Without Path Validation
GHSA-8ccj-p46r-jwqqHigh· 8.2PraisonAI: PRAISONAI_CALL_AUTH=disabled environment variable unconditionally disables authentication
PraisonAI: PRAISONAI_CALL_AUTH=disabled environment variable unconditionally disables authentication
GHSA-6jcq-6546-qrrwHigh· 8.8PraisonAI SandlockSandbox falls back to unrestricted subprocess execution when Landlock is unavailable
PraisonAI SandlockSandbox falls back to unrestricted subprocess execution when Landlock is unavailable
CVE-2026-47393Critical· 9.8PraisonAI `deploy --type api` emits a Flask server with authentication disabled by default
PraisonAI `deploy --type api` emits a Flask server with authentication disabled by default
CVE-2026-47397HighPraisonAI has an Arbitrary File Write in Python API
PraisonAI has an Arbitrary File Write in Python API
CVE-2026-47394HighPraisonAI vulnerable to unauthenticated arbitrary file read via MCP workflow.show, workflow.validate, deploy.validate
PraisonAI vulnerable to unauthenticated arbitrary file read via MCP workflow.show, workflow.validate, deploy.validate
CVE-2026-47398High· 8.1PraisonAI: Arbitrary code execution via unguarded `spec.loader.exec_module` in `agents_generator.py` - sibling of CVE-2026-44334
PraisonAI: Arbitrary code execution via unguarded `spec.loader.exec_module` in `agents_generator.py` - sibling of CVE-2026-44334
CVE-2026-44340High· 7.5PraisonAI's symlink-extraction bypass of `_safe_extractall` writes outside `dest_dir`
PraisonAI's symlink-extraction bypass of `_safe_extractall` writes outside `dest_dir`
CVE-2026-44338High· 7.3PoCPraisonAI ships and generates a legacy API server with authentication disabled by default, allowing unauthenticated workflow execution
PraisonAI ships and generates a legacy API server with authentication disabled by default, allowing unauthenticated workflow execution
CVE-2026-44337Medium· 6.3PraisonAI knowledge-store backends interpolate unvalidated collection names into SQL and CQL queries
PraisonAI knowledge-store backends interpolate unvalidated collection names into SQL and CQL queries
CVE-2026-44334High· 8.4PraisonAI has unauthenticated RCE via `tool_override.py` (CVE-2026-40287 patch bypass)
PraisonAI has unauthenticated RCE via `tool_override.py` (CVE-2026-40287 patch bypass)
CVE-2026-41496High· 8.1PraisonAI: SQL Injection via unvalidated `table_prefix` in 9 conversation store backends (incomplete fix for CVE-2026-40315)
PraisonAI: SQL Injection via unvalidated `table_prefix` in 9 conversation store backends (incomplete fix for CVE-2026-40315)
CVE-2026-40315MediumPraisonAI: SQLiteConversationStore didn't validate table_prefix when constructing SQL queries
PraisonAI: SQLiteConversationStore didn't validate table_prefix when constructing SQL queries
CVE-2026-40116High· 7.5PraisonAI: Unauthenticated WebSocket Endpoint Proxies to Paid OpenAI Realtime API Without Rate Limits
PraisonAI: Unauthenticated WebSocket Endpoint Proxies to Paid OpenAI Realtime API Without Rate Limits
CVE-2026-40151Medium· 5.3PoCPraisonAI: Unauthenticated Information Disclosure of Agent Instructions via /api/agents in AgentOS
PraisonAI: Unauthenticated Information Disclosure of Agent Instructions via /api/agents in AgentOS
CVE-2026-40159Medium· 5.5PraisonAI Vulnerable to Sensitive Environment Variable Exposure via Untrusted MCP Subprocess Execution
PraisonAI Vulnerable to Sensitive Environment Variable Exposure via Untrusted MCP Subprocess Execution
CVE-2026-40113High· 8.4PraisonAI Vulnerable to Argument Injection into Cloud Run Environment Variables via Unsanitized Comma in gcloud --set-env-vars
PraisonAI Vulnerable to Argument Injection into Cloud Run Environment Variables via Unsanitized Comma in gcloud --set-env-vars
CVE-2026-40148Medium· 6.5PraisonAI Vulnerable to Decompression Bomb DoS via Recipe Bundle Extraction Without Size Limits
PraisonAI Vulnerable to Decompression Bomb DoS via Recipe Bundle Extraction Without Size Limits
CVE-2026-40112Medium· 5.4PraisonAI Vulnerable to Stored XSS via Unsanitized Agent Output in HTML Rendering (nh3 Not a Required Dependency)
PraisonAI Vulnerable to Stored XSS via Unsanitized Agent Output in HTML Rendering (nh3 Not a Required Dependency)
CVE-2026-40114High· 7.2PraisonAI Vulnerable to Server-Side Request Forgery via Unvalidated webhook_url in Jobs API
PraisonAI Vulnerable to Server-Side Request Forgery via Unvalidated webhook_url in Jobs API
CVE-2026-40149High· 7.9PraisonAI: Unauthenticated Allow-List Manipulation Bypasses Agent Tool Approval Safety Controls
PraisonAI: Unauthenticated Allow-List Manipulation Bypasses Agent Tool Approval Safety Controls
CVE-2026-40158High· 8.6PraisonAI Vulnerable to Code Injection and Protection Mechanism Failure
PraisonAI Vulnerable to Code Injection and Protection Mechanism Failure
CVE-2026-40115Medium· 6.2PraisonAI has Unrestricted Upload Size in WSGI Recipe Registry Server that Enables Memory Exhaustion DoS
PraisonAI has Unrestricted Upload Size in WSGI Recipe Registry Server that Enables Memory Exhaustion DoS
CVE-2026-40156High· 7.8PraisonAI Vulnerable to Implicit Execution of Arbitrary Code via Automatic `tools.py` Loading
PraisonAI Vulnerable to Implicit Execution of Arbitrary Code via Automatic `tools.py` Loading
CVE-2026-39891High· 8.8PraisonAI has Template Injection in Agent Tool Definitions
PraisonAI has Template Injection in Agent Tool Definitions
CVE-2026-39889High· 7.5PraisonAI Has Unauthenticated SSE Event Stream that Exposes All Agent Activity in A2U Server
PraisonAI Has Unauthenticated SSE Event Stream that Exposes All Agent Activity in A2U Server