VulnSea

praisonaiagents has 35 CVEs on record. Disclosures have slowed: 9 in the last 90 days after 26 in the 90 before. The busiest recent month was June 2026 with 12. The median CVSS is 7.8 (high), with 4 rated critical. None have a confirmed exploitation report. The dominant weakness classes are CWE-918 (7) and CWE-306 (5).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
7.8
Publish → KEV
Last 90 days
9 prev 26

Products

  • praisonaiagents 35
35
Total CVEs
4
Critical
0
CISA KEV
0
Exploited

praisonaiagents vulnerabilities

CVEs affecting praisonaiagents, newest first. Open any entry for full detail, references, and exploit status.

35 CVEsRSS

CVE-2026-55528High· 8.2
4w ago

praisonaiagents: AgentServer declares auth_token but never enforces it on any route

praisonaiagents: AgentServer declares auth_token but never enforces it on any route

Twilightpraisonaiagents · praisonaiagentsEPSS 0.27%via OSV
CVE-2026-55526High· 8.5
4w ago

praisonaiagents has an SSRF protection bypass in `spider_tools._host_is_blocked()` via DNS-resolved hostnames (`127.0.0.1.nip.io`)

praisonaiagents has an SSRF protection bypass in `spider_tools._host_is_blocked()` via DNS-resolved hostnames (`127.0.0.1.nip.io`)

Twilightpraisonaiagents · praisonaiagentsEPSS 0.21%via OSV
CVE-2026-55530Medium· 6.1
4w ago

praisonaiagents: ast_grep_rewrite rewrites arbitrary files without the @require_approval gate enforced on every sibling mutation tool

praisonaiagents: ast_grep_rewrite rewrites arbitrary files without the @require_approval gate enforced on every sibling mutation tool

Sunlitpraisonaiagents · praisonaiagentsEPSS 0.12%via OSV
CVE-2026-55527High· 7.1
4w ago

praisonaiagents vulnerable to arbitrary file write via unsanitized `user_id` in `FileMemory.__init__()` — path traversal to any writable …

praisonaiagents vulnerable to arbitrary file write via unsanitized `user_id` in `FileMemory.__init__()` — path traversal to any writable location

Twilightpraisonaiagents · praisonaiagentsEPSS 0.32%via OSV
CVE-2026-55525High· 7.5
4w ago

praisonaiagents web_crawl vulnerable to SSRF via redirect-following

praisonaiagents web_crawl vulnerable to SSRF via redirect-following

Twilightpraisonaiagents · praisonaiagentsEPSS 0.29%via OSV
CVE-2026-55524High· 7.5
1mo ago

PraisonAI is a multi-agent teams system

PraisonAI is a multi-agent teams system. In versions prior to 1.6.58, the web_crawl tool performs its SSRF check only on the initially supplied URL, allowing the protection to be bypassed so the tool connects to attacker-chosen internal …

Twilightpraisonaiagents · praisonaiagentsEPSS 0.19%via NVD
CVE-2026-55522High· 7.8
1mo ago

PraisonAI is a multi-agent teams system

PraisonAI is a multi-agent teams system. In versions 3.9.26 through 4.6.57 of praiseonai and 0.12.12 through 1.6.57 of praiseonaiagents, the workflow "include" feature is vulnerable to code execution. Workflow._execute_include() implicit…

Twilightpraisonaiagents · praisonaiagentsEPSS 0.15%via NVD
CVE-2026-55523High
1mo ago

PraisonAI is a multi-agent teams system

PraisonAI is a multi-agent teams system. In versions 1.5.128 through 1.6.57, the praisonaiagents.tools.web_crawl_tools.web_crawl() function is vulnerable to server-side request forgery. While it validates the initially supplied URL and b…

Twilightpraisonaiagents · praisonaiagentsEPSS 0.36%via NVD
CVE-2026-56074Medium· 5.5
2mo ago

PraisonAI: Coarse-Grained Tool Approval Cache Bypasses Per-Invocation Consent for Shell Commands

PraisonAI: Coarse-Grained Tool Approval Cache Bypasses Per-Invocation Consent for Shell Commands

Sunlitpraisonaiagents · praisonaiagentsEPSS 0.17%via OSV
CVE-2026-57118Critical· 9.8
3mo ago

PraisonAI AgentTeam.launch exposes unauthenticated remote agent listing and invocation endpoints

PraisonAI AgentTeam.launch exposes unauthenticated remote agent listing and invocation endpoints

Midnightpraisonaiagents · praisonaiagentsvia OSV
CVE-2026-57143High· 8.8
3mo ago

PraisonAI: Server-Side Request Forgery (SSRF) in SearxNG / search_web tools via attacker-controlled searxng_url parameter

PraisonAI: Server-Side Request Forgery (SSRF) in SearxNG / search_web tools via attacker-controlled searxng_url parameter

Twilightpraisonaiagents · praisonaiagentsvia OSV
GHSA-35w5-pcw4-jx94Medium· 4.3
3mo ago

PraisonAI: Unauthenticated Event Injection via SSE `/publish` Endpoint

PraisonAI: Unauthenticated Event Injection via SSE `/publish` Endpoint

Sunlitpraisonaiagents · praisonaiagentsvia GHSA
GHSA-vmf9-xx9w-86wxHigh· 8.3
3mo ago

PraisonAI ToolsMCPServer legacy SSE transport accepts attacker Host/Origin and exposes registered tools

PraisonAI ToolsMCPServer legacy SSE transport accepts attacker Host/Origin and exposes registered tools

Twilightpraisonaiagents · praisonaiagentsvia GHSA
GHSA-6h9p-93hq-q7h6Medium· 6.5
3mo ago

PraisonAI: SpiderTools redirect-target SSRF protection bypass

PraisonAI: SpiderTools redirect-target SSRF protection bypass

Sunlitpraisonaiagents · praisonaiagentsvia GHSA
GHSA-pv2j-rghr-v5r9Medium· 6.5
3mo ago

PraisonAI: execute_code sandbox bypass: str.format C-level attribute access reads every blocklisted dunder

PraisonAI: execute_code sandbox bypass: str.format C-level attribute access reads every blocklisted dunder

Sunlitpraisonaiagents · praisonaiagentsvia GHSA
GHSA-x227-pf99-vffgCritical· 9.8
3mo ago

PraisonAI: MCP SSE transport binds 0.0.0.0 with no authentication and no Origin validation; bundled SecurityConfig is never wired in

PraisonAI: MCP SSE transport binds 0.0.0.0 with no authentication and no Origin validation; bundled SecurityConfig is never wired in

Midnightpraisonaiagents · praisonaiagentsvia GHSA
GHSA-vxgj-xg5c-p4h7High· 8.5
3mo ago

praisonaiagents: SSRF guard validates literal IPs only and never resolves DNS

praisonaiagents: SSRF guard validates literal IPs only and never resolves DNS

Twilightpraisonaiagents · praisonaiagentsvia GHSA
GHSA-2rcg-mm5h-xchxHigh· 7.5
3mo ago

PraisonAI: Arbitrary File Read via `@file:` Mention Path Traversal

PraisonAI: Arbitrary File Read via `@file:` Mention Path Traversal

Twilightpraisonaiagents · praisonaiagentsvia GHSA
GHSA-x8cv-xmq7-p8xpCritical· 9.8
3mo ago

PraisonAI AgentTeam.launch exposes unauthenticated remote agent listing and invocation endpoints

PraisonAI AgentTeam.launch exposes unauthenticated remote agent listing and invocation endpoints

Midnightpraisonaiagents · praisonaiagentsvia GHSA
GHSA-c969-5x3p-vq3vHigh· 8.1
3mo ago

PraisonAI: IMAP Command Injection via Unsanitized Email Search Parameters

PraisonAI: IMAP Command Injection via Unsanitized Email Search Parameters

Twilightpraisonaiagents · praisonaiagentsvia GHSA
GHSA-4pcv-mg8v-vrgfHigh· 8.8
3mo ago

PraisonAI: Server-Side Request Forgery (SSRF) in SearxNG / search_web tools via attacker-controlled searxng_url parameter

PraisonAI: Server-Side Request Forgery (SSRF) in SearxNG / search_web tools via attacker-controlled searxng_url parameter

Twilightpraisonaiagents · praisonaiagentsvia GHSA
CVE-2026-47395Medium· 5.5
3mo ago

PraisonAI CLI automatically resolves @url mentions in prompt text and can read loopback URLs into model context

PraisonAI CLI automatically resolves @url mentions in prompt text and can read loopback URLs into model context

Sunlitpraisonaiagents · praisonaiagentsEPSS 0.18%via OSV
CVE-2026-47390Medium· 5.5
3mo ago

PraisonAI spider_tools SSRF protection bypass via alternate loopback host encodings

PraisonAI spider_tools SSRF protection bypass via alternate loopback host encodings

Sunlitpraisonaiagents · praisonaiagentsEPSS 0.18%via OSV
CVE-2026-44339High· 8.6
4mo ago

PraisonAI has unsafe tool resolution in `ToolExecutionMixin.execute_tool`: undeclared `__main__` callables execute

PraisonAI has unsafe tool resolution in `ToolExecutionMixin.execute_tool`: undeclared `__main__` callables execute

Twilightpraisonaiagents · praisonaiagentsEPSS 0.36%via OSV
CVE-2026-44335Critical· 9.8
4mo ago

PraisonAI has an SSRF bypass

PraisonAI has an SSRF bypass

Midnightpraisonaiagents · praisonaiagentsEPSS 0.38%via OSV
GHSA-x462-jjpc-q4q4High· 8.1
5mo ago

PraisonAI: Cross-Origin Agent Execution via Hardcoded Wildcard CORS and Missing Authentication on AGUI Endpoint

PraisonAI: Cross-Origin Agent Execution via Hardcoded Wildcard CORS and Missing Authentication on AGUI Endpoint

Twilightpraisonaiagents · praisonaiagentsvia OSV
CVE-2026-40153High· 7.4
5mo ago

PraisonAIAgents: Environment Variable Secret Exfiltration via os.path.expandvars() Bypassing shell=False in Shell Tool

PraisonAIAgents: Environment Variable Secret Exfiltration via os.path.expandvars() Bypassing shell=False in Shell Tool

Twilightpraisonaiagents · praisonaiagentsEPSS 0.27%via OSV
CVE-2026-40160High
5mo ago

PraisonAIAgents: SSRF via unvalidated URL in `web_crawl` httpx fallback

PraisonAIAgents: SSRF via unvalidated URL in `web_crawl` httpx fallback

Twilightpraisonaiagents · praisonaiagentsEPSS 0.36%via OSV
CVE-2026-40117Medium· 6.2
5mo ago

PraisonAIAgents: Arbitrary File Read via read_skill_file Missing Workspace Boundary and Approval Gate

PraisonAIAgents: Arbitrary File Read via read_skill_file Missing Workspace Boundary and Approval Gate

Sunlitpraisonaiagents · praisonaiagentsEPSS 0.23%via OSV
CVE-2026-40287High· 8.4
5mo ago

PraisonAI Vulnerable to RCE via Automatic tools.py Import

PraisonAI Vulnerable to RCE via Automatic tools.py Import

Twilightpraisonaiagents · praisonaiagentsEPSS 0.25%via OSV
praisonaiagents vulnerabilities (CVEs) · VulnSea