praisonaiagents has 35 CVEs on record. Disclosures have slowed: 9 in the last 90 days after 26 in the 90 before. The busiest recent month was June 2026 with 12. The median CVSS is 7.8 (high), with 4 rated critical. None have a confirmed exploitation report. The dominant weakness classes are CWE-918 (7) and CWE-306 (5).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 7.8
- Publish → KEV
- —
- Last 90 days
- 9 prev 26
Worst active — by depth score
GHSA-x8cv-xmq7-p8xpCritical· 9.8PraisonAI AgentTeam.launch exposes unauthenticated remote agent listing and invocation endpoints54GHSA-x227-pf99-vffgCritical· 9.8PraisonAI: MCP SSE transport binds 0.0.0.0 with no authentication and no Origin validation; bundled SecurityConfig is never wired in54CVE-2026-57118Critical· 9.8PraisonAI AgentTeam.launch exposes unauthenticated remote agent listing and invocation endpoints54CVE-2026-44335Critical· 9.8PraisonAI has an SSRF bypass54GHSA-4pcv-mg8v-vrgfHigh· 8.8PraisonAI: Server-Side Request Forgery (SSRF) in SearxNG / search_web tools via attacker-controlled searxng_url parameter48
praisonaiagents vulnerabilities
CVEs affecting praisonaiagents, newest first. Open any entry for full detail, references, and exploit status.
35 CVEsRSS
CVE-2026-55528High· 8.2praisonaiagents: AgentServer declares auth_token but never enforces it on any route
praisonaiagents: AgentServer declares auth_token but never enforces it on any route
CVE-2026-55526High· 8.5praisonaiagents has an SSRF protection bypass in `spider_tools._host_is_blocked()` via DNS-resolved hostnames (`127.0.0.1.nip.io`)
praisonaiagents has an SSRF protection bypass in `spider_tools._host_is_blocked()` via DNS-resolved hostnames (`127.0.0.1.nip.io`)
CVE-2026-55530Medium· 6.1praisonaiagents: ast_grep_rewrite rewrites arbitrary files without the @require_approval gate enforced on every sibling mutation tool
praisonaiagents: ast_grep_rewrite rewrites arbitrary files without the @require_approval gate enforced on every sibling mutation tool
CVE-2026-55527High· 7.1praisonaiagents vulnerable to arbitrary file write via unsanitized `user_id` in `FileMemory.__init__()` — path traversal to any writable …
praisonaiagents vulnerable to arbitrary file write via unsanitized `user_id` in `FileMemory.__init__()` — path traversal to any writable location
CVE-2026-55525High· 7.5praisonaiagents web_crawl vulnerable to SSRF via redirect-following
praisonaiagents web_crawl vulnerable to SSRF via redirect-following
CVE-2026-55524High· 7.5PraisonAI is a multi-agent teams system
PraisonAI is a multi-agent teams system. In versions prior to 1.6.58, the web_crawl tool performs its SSRF check only on the initially supplied URL, allowing the protection to be bypassed so the tool connects to attacker-chosen internal …
CVE-2026-55522High· 7.8PraisonAI is a multi-agent teams system
PraisonAI is a multi-agent teams system. In versions 3.9.26 through 4.6.57 of praiseonai and 0.12.12 through 1.6.57 of praiseonaiagents, the workflow "include" feature is vulnerable to code execution. Workflow._execute_include() implicit…
CVE-2026-55523HighPraisonAI is a multi-agent teams system
PraisonAI is a multi-agent teams system. In versions 1.5.128 through 1.6.57, the praisonaiagents.tools.web_crawl_tools.web_crawl() function is vulnerable to server-side request forgery. While it validates the initially supplied URL and b…
CVE-2026-56074Medium· 5.5PraisonAI: Coarse-Grained Tool Approval Cache Bypasses Per-Invocation Consent for Shell Commands
PraisonAI: Coarse-Grained Tool Approval Cache Bypasses Per-Invocation Consent for Shell Commands
CVE-2026-57118Critical· 9.8PraisonAI AgentTeam.launch exposes unauthenticated remote agent listing and invocation endpoints
PraisonAI AgentTeam.launch exposes unauthenticated remote agent listing and invocation endpoints
CVE-2026-57143High· 8.8PraisonAI: Server-Side Request Forgery (SSRF) in SearxNG / search_web tools via attacker-controlled searxng_url parameter
PraisonAI: Server-Side Request Forgery (SSRF) in SearxNG / search_web tools via attacker-controlled searxng_url parameter
GHSA-35w5-pcw4-jx94Medium· 4.3PraisonAI: Unauthenticated Event Injection via SSE `/publish` Endpoint
PraisonAI: Unauthenticated Event Injection via SSE `/publish` Endpoint
GHSA-vmf9-xx9w-86wxHigh· 8.3PraisonAI ToolsMCPServer legacy SSE transport accepts attacker Host/Origin and exposes registered tools
PraisonAI ToolsMCPServer legacy SSE transport accepts attacker Host/Origin and exposes registered tools
GHSA-6h9p-93hq-q7h6Medium· 6.5PraisonAI: SpiderTools redirect-target SSRF protection bypass
PraisonAI: SpiderTools redirect-target SSRF protection bypass
GHSA-pv2j-rghr-v5r9Medium· 6.5PraisonAI: execute_code sandbox bypass: str.format C-level attribute access reads every blocklisted dunder
PraisonAI: execute_code sandbox bypass: str.format C-level attribute access reads every blocklisted dunder
GHSA-x227-pf99-vffgCritical· 9.8PraisonAI: MCP SSE transport binds 0.0.0.0 with no authentication and no Origin validation; bundled SecurityConfig is never wired in
PraisonAI: MCP SSE transport binds 0.0.0.0 with no authentication and no Origin validation; bundled SecurityConfig is never wired in
GHSA-vxgj-xg5c-p4h7High· 8.5praisonaiagents: SSRF guard validates literal IPs only and never resolves DNS
praisonaiagents: SSRF guard validates literal IPs only and never resolves DNS
GHSA-2rcg-mm5h-xchxHigh· 7.5PraisonAI: Arbitrary File Read via `@file:` Mention Path Traversal
PraisonAI: Arbitrary File Read via `@file:` Mention Path Traversal
GHSA-x8cv-xmq7-p8xpCritical· 9.8PraisonAI AgentTeam.launch exposes unauthenticated remote agent listing and invocation endpoints
PraisonAI AgentTeam.launch exposes unauthenticated remote agent listing and invocation endpoints
GHSA-c969-5x3p-vq3vHigh· 8.1PraisonAI: IMAP Command Injection via Unsanitized Email Search Parameters
PraisonAI: IMAP Command Injection via Unsanitized Email Search Parameters
GHSA-4pcv-mg8v-vrgfHigh· 8.8PraisonAI: Server-Side Request Forgery (SSRF) in SearxNG / search_web tools via attacker-controlled searxng_url parameter
PraisonAI: Server-Side Request Forgery (SSRF) in SearxNG / search_web tools via attacker-controlled searxng_url parameter
CVE-2026-47395Medium· 5.5PraisonAI CLI automatically resolves @url mentions in prompt text and can read loopback URLs into model context
PraisonAI CLI automatically resolves @url mentions in prompt text and can read loopback URLs into model context
CVE-2026-47390Medium· 5.5PraisonAI spider_tools SSRF protection bypass via alternate loopback host encodings
PraisonAI spider_tools SSRF protection bypass via alternate loopback host encodings
CVE-2026-44339High· 8.6PraisonAI has unsafe tool resolution in `ToolExecutionMixin.execute_tool`: undeclared `__main__` callables execute
PraisonAI has unsafe tool resolution in `ToolExecutionMixin.execute_tool`: undeclared `__main__` callables execute
CVE-2026-44335Critical· 9.8PraisonAI has an SSRF bypass
PraisonAI has an SSRF bypass
GHSA-x462-jjpc-q4q4High· 8.1PraisonAI: Cross-Origin Agent Execution via Hardcoded Wildcard CORS and Missing Authentication on AGUI Endpoint
PraisonAI: Cross-Origin Agent Execution via Hardcoded Wildcard CORS and Missing Authentication on AGUI Endpoint
CVE-2026-40153High· 7.4PraisonAIAgents: Environment Variable Secret Exfiltration via os.path.expandvars() Bypassing shell=False in Shell Tool
PraisonAIAgents: Environment Variable Secret Exfiltration via os.path.expandvars() Bypassing shell=False in Shell Tool
CVE-2026-40160HighPraisonAIAgents: SSRF via unvalidated URL in `web_crawl` httpx fallback
PraisonAIAgents: SSRF via unvalidated URL in `web_crawl` httpx fallback
CVE-2026-40117Medium· 6.2PraisonAIAgents: Arbitrary File Read via read_skill_file Missing Workspace Boundary and Approval Gate
PraisonAIAgents: Arbitrary File Read via read_skill_file Missing Workspace Boundary and Approval Gate
CVE-2026-40287High· 8.4PraisonAI Vulnerable to RCE via Automatic tools.py Import
PraisonAI Vulnerable to RCE via Automatic tools.py Import