praisonai
npm9 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting praisonaipage 1 of 1
- CVE-2026-57133HIGHCVSS 8.8EG 8.8✓ Fixed in 1.7.22026-06-18
npm PraisonAI utility shell safe-command wrapper allowlist bypass via shell chaining ## Summary The published npm package `praisonai` ships `dist/tools/utility-tools.js`, which exports a `shell(command)` helper described in source as: `…
- CVE-2026-57134HIGHCVSS 8.2EG 8.2✓ Fixed in 1.7.22026-06-18
npm PraisonAI MCPSecurity Basic/OAuth authentication policies accept invalid credentials without validation ## Summary The published npm package `praisonai` exports an `MCPSecurity` helper described in source as: ```text MCP Security - …
- CVE-2026-57135HIGHCVSS 7.6EG 7.6✓ Fixed in 1.7.22026-06-18
npm PraisonAI SandboxExecutor network-isolated mode does not block non-proxy-aware network clients ## Summary The published npm package `praisonai` exports a TypeScript `SandboxExecutor` with a `network-isolated` mode. The CLI lists that…
- CVE-2026-57136HIGHCVSS 8.8EG 8.8✓ Fixed in 1.7.22026-06-18
npm PraisonAI SandboxExecutor allowedCommands bypass via shell chaining ## Summary The published npm package `praisonai` exports `SandboxExecutor`, `CommandValidator`, and `sandboxExec` as "safe command execution with restrictions." When…
- CVE-2026-57137HIGHCVSS 8.8EG 8.8✓ Fixed in 1.7.22026-06-18
npm PraisonAI AgentLoop onToolCall approval runs after tool execution ## Summary The published npm package `praisonai` exports `createAgentLoop()`, whose `onToolCall` callback is documented and exampled as an approval hook. The implement…
- CVE-2026-57138CRITICALCVSS 9.9EG 9.9✓ Fixed in 1.7.22026-06-18
npm PraisonAI codeMode sandbox escape via Function constructor ## Summary The published npm package `praisonai` exports a TypeScript built-in tool named `codeMode`. The package describes this tool as executing code in a sandboxed environ…
- CVE-2026-57139CRITICALCVSS 9.8EG 9.8✓ Fixed in 1.7.22026-06-18
npm PraisonAI MCPServer exposes unauthenticated HTTP tools/call ## Summary The published npm package `praisonai` exports a TypeScript `MCPServer` that can expose tools, resources, and prompts over an HTTP JSON-RPC transport with: ```ts …
- CVE-2026-57140CRITICALCVSS 9.4EG 9.4✓ Fixed in 1.7.22026-06-18
npm PraisonAI AgentOS exposes unauthenticated agent listing and invocation ## Summary The published npm package `praisonai` ships a TypeScript `AgentOS` HTTP server that defaults to `host: "0.0.0.0"` and registers sensitive agent routes …
- CVE-2026-57141CRITICALCVSS 9.8EG 9.8✓ Fixed in 1.7.22026-06-18
PraisonAI: Remote Code Execution via Sandbox Escape in `codeMode` Tool ## Summary The `codeMode` tool in `src/praisonai-ts/src/tools/builtins/code-mode.ts` uses `new Function()` with a `with(sandbox)` pattern to execute LLM-generated cod…
Check whether praisonai is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for praisonai CVEs against the assets you own.
Start Free Scan →