praisonai has 92 CVEs on record. Disclosures have slowed: 12 in the last 90 days after 80 in the 90 before. The busiest recent month was June 2026 with 50. The median CVSS is 8.1 (high), with 13 rated critical. None have a confirmed exploitation report. The dominant weakness classes are CWE-306 (15) and CWE-863 (12).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 8.1
- Publish → KEV
- —
- Last 90 days
- 12 prev 80
Weakness classes
Products
- praisonai 92
Worst active — by depth score
GHSA-vmmj-pfw7-fjwpCritical· 9.9npm PraisonAI codeMode sandbox escape via Function constructor54GHSA-p75f-6fp4-p57wCritical· 9.8PraisonAI: Missing Authentication for Critical Function and Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in praisonai54GHSA-p69m-4f92-2v84Critical· 9.8PraisonAI: Remote Code Execution via Sandbox Escape in `codeMode` Tool54GHSA-j4hj-7hfh-g2f4Critical· 9.8praisonai: recipe serve auth middleware silently disables itself when no secret is set54GHSA-j4f3-55x4-r6q2Critical· 9.8npm PraisonAI MCPServer exposes unauthenticated HTTP tools/call54
praisonai vulnerabilities
CVEs affecting praisonai, newest first. Open any entry for full detail, references, and exploit status.
92 CVEsRSS
GHSA-22cj-m4wf-fv2cHigh· 7.5PraisonAI Dynamic Context history and terminal tools read files outside configured storage via path traversal
PraisonAI Dynamic Context history and terminal tools read files outside configured storage via path traversal
GHSA-5qw8-f2g9-ff29High· 8.2PraisonAI recipe serve Typer command bypasses the non-localhost authentication guard
PraisonAI recipe serve Typer command bypasses the non-localhost authentication guard
GHSA-qvpf-j64c-jmhrHigh· 8.3PraisonAI Slack app_mention bypasses configured user/channel authorization
PraisonAI Slack app_mention bypasses configured user/channel authorization
GHSA-j7qx-p75m-wp7gHigh· 7.5PraisonAI dynamic-context artifact tools read arbitrary host files outside artifact storage
PraisonAI dynamic-context artifact tools read arbitrary host files outside artifact storage
GHSA-fc26-m9pf-v56qHigh· 8.6PraisonAI LinearBot processes unsigned webhooks when LINEAR_WEBHOOK_SECRET is missing
PraisonAI LinearBot processes unsigned webhooks when LINEAR_WEBHOOK_SECRET is missing
GHSA-63v4-w882-g4x2High· 8.8PraisonAI: HTTPApproval dashboard renders tool arguments as raw HTML, allowing approval-page XSS to approve dangerous tools
PraisonAI: HTTPApproval dashboard renders tool arguments as raw HTML, allowing approval-page XSS to approve dangerous tools
GHSA-v847-hxxw-3pxgHigh· 7.8PraisonAI recipe.run_stream skips dangerous-tool policy enforcement
PraisonAI recipe.run_stream skips dangerous-tool policy enforcement
GHSA-w6h2-fr4q-xvxvHigh· 8.8PraisonAI: Compute-bridged file tools allow shell command injection
PraisonAI: Compute-bridged file tools allow shell command injection
GHSA-p4pj-vh7h-6cqhHigh· 7.5PraisonAI: Unauthenticated Local File Inclusion via agent_file path in PraisonAI Jobs API
PraisonAI: Unauthenticated Local File Inclusion via agent_file path in PraisonAI Jobs API
GHSA-4869-x4pr-q22xCritical· 9.8PraisonAI: Unauthenticated RCE via Jobs API + Approval Bypass
PraisonAI: Unauthenticated RCE via Jobs API + Approval Bypass
GHSA-j4hj-7hfh-g2f4Critical· 9.8praisonai: recipe serve auth middleware silently disables itself when no secret is set
praisonai: recipe serve auth middleware silently disables itself when no secret is set
GHSA-fq2m-6wqh-x44gCritical· 9.8PraisonAI: Jobs API exposes agent-execution endpoints with no authentication
PraisonAI: Jobs API exposes agent-execution endpoints with no authentication
GHSA-rjvw-7vvw-549vHigh· 7.2PraisonAI: Jobs webhook SSRF protection bypass via DNS rebinding
PraisonAI: Jobs webhook SSRF protection bypass via DNS rebinding
GHSA-892r-p3jq-jp24Critical· 9.8PraisonAI: AgentOS remains unauthenticated after incomplete fix version and allows remote agent invocation
PraisonAI: AgentOS remains unauthenticated after incomplete fix version and allows remote agent invocation
GHSA-x92v-rpx6-p6cwHigh· 8.6PraisonAI: Webhook signature verification skipped (fail-open) when secret unset, allowing forged inbound webhooks (WhatsApp & Linear bots)
PraisonAI: Webhook signature verification skipped (fail-open) when secret unset, allowing forged inbound webhooks (WhatsApp & Linear bots)
GHSA-p75f-6fp4-p57wCritical· 9.8PraisonAI: Missing Authentication for Critical Function and Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in praisonai
PraisonAI: Missing Authentication for Critical Function and Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in praisonai
GHSA-gcq3-mfvh-3x25High· 7.3PraisonAI Code agent tools fail open without a workspace boundary
PraisonAI Code agent tools fail open without a workspace boundary
GHSA-f44v-7qgw-9gh9High· 8.1PraisonAI GitHub template cache path traversal allows outside-cache file write and directory deletion
PraisonAI GitHub template cache path traversal allows outside-cache file write and directory deletion
GHSA-4qq2-2j2x-x62cHigh· 8.2npm PraisonAI MCPSecurity Basic/OAuth authentication policies accept invalid credentials without validation
npm PraisonAI MCPSecurity Basic/OAuth authentication policies accept invalid credentials without validation
GHSA-vmmj-pfw7-fjwpCritical· 9.9npm PraisonAI codeMode sandbox escape via Function constructor
npm PraisonAI codeMode sandbox escape via Function constructor
GHSA-gqmf-56h7-rrpfHigh· 7.6npm PraisonAI SandboxExecutor network-isolated mode does not block non-proxy-aware network clients
npm PraisonAI SandboxExecutor network-isolated mode does not block non-proxy-aware network clients
GHSA-vjv9-7m7j-h833High· 8.8npm PraisonAI SandboxExecutor allowedCommands bypass via shell chaining
npm PraisonAI SandboxExecutor allowedCommands bypass via shell chaining
GHSA-p69m-4f92-2v84Critical· 9.8PraisonAI: Remote Code Execution via Sandbox Escape in `codeMode` Tool
PraisonAI: Remote Code Execution via Sandbox Escape in `codeMode` Tool
GHSA-9752-mhqh-h34fCritical· 9.4npm PraisonAI AgentOS exposes unauthenticated agent listing and invocation
npm PraisonAI AgentOS exposes unauthenticated agent listing and invocation
GHSA-j4f3-55x4-r6q2Critical· 9.8npm PraisonAI MCPServer exposes unauthenticated HTTP tools/call
npm PraisonAI MCPServer exposes unauthenticated HTTP tools/call
GHSA-h2w2-v7j6-xqm4High· 8.8npm PraisonAI AgentLoop onToolCall approval runs after tool execution
npm PraisonAI AgentLoop onToolCall approval runs after tool execution
GHSA-5jv7-2mjm-h6qjHigh· 8.8npm PraisonAI utility shell safe-command wrapper allowlist bypass via shell chaining
npm PraisonAI utility shell safe-command wrapper allowlist bypass via shell chaining
GHSA-7qw2-w5rc-37x2High· 7.8PraisonAI recipe workflow policy can be bypassed by declaring and YAML-approving dangerous tools outside TEMPLATE.yaml
PraisonAI recipe workflow policy can be bypassed by declaring and YAML-approving dangerous tools outside TEMPLATE.yaml
GHSA-jxcw-qp4h-6jfqHigh· 7.5PraisonAI A2U incomplete authentication fix leaves current serve command unauthenticated by default
PraisonAI A2U incomplete authentication fix leaves current serve command unauthenticated by default
GHSA-29w3-p9w9-wc47Critical· 9.1PraisonAI: Arbitrary File Read/Write via `multiedit` Tool Without Path Validation
PraisonAI: Arbitrary File Read/Write via `multiedit` Tool Without Path Validation