praisonai
npm9 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting praisonaipage 1 of 1
- CVE-2026-57133HIGHCVSS 8.8EG 8.8✓ Fixed in 1.7.22026-06-18
PraisonAI is a multi-agent teams system. From 1.5.1 until 1.7.2, the shell() helper exported from src/praisonai-ts/src/tools/utility-tools.ts checks only the first whitespace-delimited token against safeCommands and then passes the complet…
- CVE-2026-57134HIGHCVSS 8.2EG 8.2✓ Fixed in 1.7.22026-06-18
PraisonAI is a multi-agent teams system. From 1.5.1 until 1.7.2, MCPSecurity.evaluatePolicy() in src/praisonai-ts/src/mcp/security.ts invokes the configured credential validator only when AuthMethod is api-key or bearer. Basic and OAuth po…
- CVE-2026-57135HIGHCVSS 7.6EG 7.6✓ Fixed in 1.7.22026-06-18
PraisonAI is a multi-agent teams system. From 1.2.3 until 1.7.2, SandboxExecutor network-isolated mode in src/praisonai-ts/src/cli/features/sandbox-executor.ts uses buildEnv() only to inject invalid http_proxy and https_proxy environment v…
- CVE-2026-57136HIGHCVSS 8.8EG 8.8✓ Fixed in 1.7.22026-06-18
PraisonAI is a multi-agent teams system. From 1.2.3 until 1.7.2, CommandValidator in src/praisonai-ts/src/cli/features/sandbox-executor.ts validates only the first whitespace-delimited executable against allowedCommands, then SandboxExecut…
- CVE-2026-57137HIGHCVSS 8.8EG 8.8✓ Fixed in 1.7.22026-06-18
PraisonAI is a multi-agent teams system. From 1.4.0 until 1.7.2, createAgentLoop() in src/praisonai-ts/src/ai/agent-loop.ts passes executable tools to generateText() before invoking the onToolCall approval callback. Because the wrapped AI …
- CVE-2026-57138CRITICALCVSS 9.9EG 9.9✓ Fixed in 1.7.22026-06-18
PraisonAI is a multi-agent teams system. From 1.4.0 until 1.7.2, codeMode in src/praisonai-ts/src/tools/builtins/code-mode.ts executes untrusted JavaScript with new Function() inside with(sandbox) and relies on a small source-code blocklis…
- CVE-2026-57139CRITICALCVSS 9.8EG 9.8✓ Fixed in 1.7.22026-06-18
PraisonAI is a multi-agent teams system. From 1.5.0 until 1.7.2, MCPServer.startHttp() in src/praisonai-ts/src/mcp/server.ts binds without a host restriction and forwards every HTTP POST request to handleRequest() without authentication or…
- CVE-2026-57140CRITICALCVSS 9.4EG 9.4✓ Fixed in 1.7.22026-06-18
PraisonAI is a multi-agent teams system. From 1.6.0 until 1.7.2, AgentOS in src/praisonai-ts/src/os/agentos.ts uses the 0.0.0.0 default from src/praisonai-ts/src/os/config.ts and registers GET /api/agents and POST /api/chat without authent…
- CVE-2026-57141CRITICALCVSS 9.8EG 9.8✓ Fixed in 1.7.22026-06-18
PraisonAI is a multi-agent teams system. Prior to 1.7.2, the codeMode tool in src/praisonai-ts/src/tools/builtins/code-mode.ts executes model-generated JavaScript with new Function() and with(sandbox), while a regular-expression blocklist …
Check whether praisonai is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for praisonai CVEs against the assets you own.
Start Free Scan →