praisonaiagents has 35 CVEs on record. Disclosures have slowed: 9 in the last 90 days after 26 in the 90 before. The busiest recent month was June 2026 with 12. The median CVSS is 7.8 (high), with 4 rated critical. None have a confirmed exploitation report. The dominant weakness classes are CWE-918 (7) and CWE-306 (5).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 7.8
- Publish → KEV
- —
- Last 90 days
- 9 prev 26
Worst active — by depth score
GHSA-x8cv-xmq7-p8xpCritical· 9.8PraisonAI AgentTeam.launch exposes unauthenticated remote agent listing and invocation endpoints54GHSA-x227-pf99-vffgCritical· 9.8PraisonAI: MCP SSE transport binds 0.0.0.0 with no authentication and no Origin validation; bundled SecurityConfig is never wired in54CVE-2026-57118Critical· 9.8PraisonAI AgentTeam.launch exposes unauthenticated remote agent listing and invocation endpoints54CVE-2026-44335Critical· 9.8PraisonAI has an SSRF bypass54GHSA-4pcv-mg8v-vrgfHigh· 8.8PraisonAI: Server-Side Request Forgery (SSRF) in SearxNG / search_web tools via attacker-controlled searxng_url parameter48
praisonaiagents vulnerabilities
CVEs affecting praisonaiagents, newest first. Open any entry for full detail, references, and exploit status.
35 CVEsRSS
CVE-2026-40150High· 7.7PraisonAIAgents has SSRF and Local File Read via Unvalidated URLs in web_crawl Tool
PraisonAIAgents has SSRF and Local File Read via Unvalidated URLs in web_crawl Tool
CVE-2026-40152Medium· 5.3PraisonAIAgents: Path Traversal via Unvalidated Glob Pattern in list_files Bypasses Workspace Boundary
PraisonAIAgents: Path Traversal via Unvalidated Glob Pattern in list_files Bypasses Workspace Boundary
CVE-2026-56078Medium· 6.5PraisonAI has Memory State Leakage and Path Traversal in MultiAgent Context Handling
PraisonAI has Memory State Leakage and Path Traversal in MultiAgent Context Handling
CVE-2026-34937High· 7.8PraisonAI: Shell Injection in run_python() via Unescaped $() Substitution
PraisonAI: Shell Injection in run_python() via Unescaped $() Substitution
CVE-2026-34954High· 8.6PraisonAI Has SSRF in FileTools.download_file() via Unvalidated URL
PraisonAI Has SSRF in FileTools.download_file() via Unvalidated URL