PraisonAI has 126 CVEs on record. Disclosures have slowed: 26 in the last 90 days after 80 in the 90 before. The busiest recent month was June 2026 with 53. The median CVSS is 8.1 (high), with 19 rated critical. None have a confirmed exploitation report. The dominant weakness classes are CWE-306 (20) and CWE-22 (14).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 8.1
- Publish → KEV
- —
- Last 90 days
- 26 prev 80
Weakness classes
Products
- praisonai 126
Worst active — by depth score
CVE-2026-56075High· 8.8PraisonAI before 4.5.128 contains an arbitrary shell command execution vulnerability where the UI modules hardcode approval_mode to auto, overriding administrator configuration from PRAISON_APPROVAL_MODE environment variable61CVE-2026-56076High· 8.1PraisonAI before 1.5.128 contains a cross-origin agent execution vulnerability in the AGUI endpoint that allows remote attackers to trigger arbitrary agent execution57GHSA-mhgx-w3w5-2rvcCritical· 10.0Duplicate Advisory: PraisonAI: CodeAgent Executes LLM-Generated Code Without Sandboxing and Leaks All Environment Secrets55CVE-2026-61445Critical· 9.9PraisonAI before 4.6.78 contains arbitrary file write and command execution vulnerabilities in the AICoder component due to missing path validation and command sanitization in LLM tool calls55GHSA-wj29-gm8v-33x8Critical· 9.9Duplicate Advisory: PraisonAI: AICoder Arbitrary File Write and Command Execution via LLM Tool Calls54
PraisonAI vulnerabilities
CVEs affecting PraisonAI, newest first. Open any entry for full detail, references, and exploit status.
126 CVEsRSS
CVE-2026-39308High· 7.1PraisonAI recipe registry publish path traversal allows out-of-root file write
PraisonAI recipe registry publish path traversal allows out-of-root file write
CVE-2026-39306High· 7.3PraisonAI recipe registry pull path traversal writes files outside the chosen output directory
PraisonAI recipe registry pull path traversal writes files outside the chosen output directory
CVE-2026-39307High· 8.1PraisonAI Has Arbitrary File Write (Zip Slip) in Templates Extraction
PraisonAI Has Arbitrary File Write (Zip Slip) in Templates Extraction
CVE-2026-34936High· 7.7PraisonAI: SSRF via Unvalidated api_base in passthrough() Fallback
PraisonAI: SSRF via Unvalidated api_base in passthrough() Fallback
CVE-2026-34955High· 8.8PraisonAI Has Sandbox Escape via shell=True and Bypassable Blocklist in SubprocessSandbox
PraisonAI Has Sandbox Escape via shell=True and Bypassable Blocklist in SubprocessSandbox
CVE-2026-34939Medium· 6.5PraisonAI Has ReDoS via Unvalidated User-Controlled Regex in MCPToolIndex.search_tools()
PraisonAI Has ReDoS via Unvalidated User-Controlled Regex in MCPToolIndex.search_tools()