praisonai
PyPI77 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting praisonaipage 2 of 2
- CVE-2026-56075HIGHCVSS 8.8EG 8.8✓ Fixed in 4.5.1282026-06-18
vulnerable: 0.0.1 ... 4.5.98 (685 versions)
PraisonAI before 4.5.128 contains an arbitrary shell command execution vulnerability where the UI modules hardcode approval_mode to auto, overriding administrator configuration from PRAISON_APPROVAL_MODE environment variable. Authenticated…
- CVE-2026-56832HIGHCVSS 8.8EG 8.8✓ Fixed in 4.6.592026-06-18
vulnerable: 4.5.10 ... 4.6.9 (176 versions)
PraisonAI DiscordApproval accepts unrelated channel messages as dangerous-tool approvals # DiscordApproval accepts unrelated channel messages as dangerous-tool approvals ## Summary `praisonai.bots.DiscordApproval` approves a pending dan…
- CVE-2026-56833HIGHCVSS 7.5EG 7.5✓ Fixed in 4.6.592026-06-18
vulnerable: 3.10.0 ... 4.6.9 (300 versions)
PraisonAI Dynamic Context history and terminal tools read files outside configured storage via path traversal # PraisonAI Dynamic Context history and terminal tools read files outside configured storage via path traversal ## Summary Pra…
- CVE-2026-56834HIGHCVSS 7.5EG 7.5✓ Fixed in 4.6.592026-06-18
vulnerable: 3.10.0 ... 4.6.9 (300 versions)
PraisonAI dynamic-context artifact tools read arbitrary host files outside artifact storage # PraisonAI dynamic-context artifact tools read arbitrary host files outside artifact storage ## Summary PraisonAI's Dynamic Context Discovery f…
- CVE-2026-56835HIGHCVSS 8.3EG 8.3✓ Fixed in 4.6.592026-06-18
vulnerable: 3.11.0 ... 4.6.9 (215 versions)
PraisonAI Slack app_mention bypasses configured user/channel authorization # PraisonAI Slack `app_mention` bypasses configured user/channel authorization ## Summary PraisonAI's Slack bot applies its configured `allowed_users`, `allowed_…
- CVE-2026-56836HIGHCVSS 8.2EG 8.2✓ Fixed in 4.6.592026-06-18
vulnerable: 4.5.112 ... 4.6.9 (79 versions)
PraisonAI recipe serve Typer command bypasses the non-localhost authentication guard # PraisonAI `recipe serve` Typer command bypasses the non-localhost authentication guard ## Summary PraisonAI's installed console entrypoint is Typer-f…
- CVE-2026-56837HIGHCVSS 8.6EG 8.6✓ Fixed in 4.6.592026-06-18
vulnerable: 4.6.56, 4.6.57, 4.6.58
PraisonAI LinearBot processes unsigned webhooks when LINEAR_WEBHOOK_SECRET is missing # PraisonAI LinearBot processes unsigned webhooks when `LINEAR_WEBHOOK_SECRET` is missing ## Summary PraisonAI's LinearBot starts a public webhook lis…
- CVE-2026-56838HIGHCVSS 7.8EG 7.8✓ Fixed in 4.6.592026-06-18
vulnerable: 4.5.100 ... 4.6.9 (101 versions)
PraisonAI recipe.run_stream skips dangerous-tool policy enforcement # PraisonAI `recipe.run_stream()` skips dangerous-tool policy enforcement ## Summary PraisonAI recipe execution blocks default-denied dangerous tools unless the caller …
- CVE-2026-56839HIGHCVSS 7.3EG 7.3✓ Fixed in 4.6.592026-06-18
vulnerable: 0.0.1 ... 4.6.9 (749 versions)
PraisonAI Code agent tools fail open without a workspace boundary # PraisonAI Code agent tools fail open without a workspace boundary ## Summary PraisonAI Code's agent-compatible `CODE_TOOLS` wrappers keep a global workspace root initia…
- CVE-2026-56840HIGHCVSS 8.8EG 8.8✓ Fixed in 4.6.592026-06-18
vulnerable: 4.5.10 ... 4.6.9 (176 versions)
PraisonAI: HTTPApproval dashboard renders tool arguments as raw HTML, allowing approval-page XSS to approve dangerous tools # HTTPApproval dashboard renders tool arguments as raw HTML, allowing approval-page XSS to approve dangerous tools…
- CVE-2026-57112HIGHCVSS 8.3EG 8.3✓ Fixed in 4.6.592026-06-18
vulnerable: 3.10.0 ... 4.6.9 (243 versions)
PraisonAI ToolsMCPServer legacy SSE transport accepts attacker Host/Origin and exposes registered tools # PraisonAI ToolsMCPServer legacy SSE transport accepts attacker Host/Origin and exposes registered tools ## Summary `praisonaiagent…
- CVE-2026-57113HIGHCVSS 8.1EG 8.1✓ Fixed in 4.6.592026-06-18
vulnerable: 2.6.0 ... 4.6.9 (370 versions)
PraisonAI GitHub template cache path traversal allows outside-cache file write and directory deletion ## Summary PraisonAI's template loader accepts GitHub template URIs with refs, for example `github:owner/repo/[email protected]`. The res…
- CVE-2026-57114HIGHCVSS 7.2EG 7.2✓ Fixed in 4.6.592026-06-18
vulnerable: 4.5.126 ... 4.6.9 (66 versions)
PraisonAI: Jobs webhook SSRF protection bypass via DNS rebinding # Jobs webhook SSRF protection bypass via DNS rebinding ## Summary PraisonAI's Async Jobs API validates `webhook_url` when a job request is parsed and again when the inter…
- CVE-2026-57116CRITICALCVSS 9.8EG 9.8✓ Fixed in 4.6.592026-06-18
vulnerable: 4.2.1 ... 4.6.9 (196 versions)
PraisonAI: AgentOS remains unauthenticated after incomplete fix version and allows remote agent invocation # AgentOS remains unauthenticated after GHSA-pm96 patched version and allows remote agent invocation ## Summary PraisonAI's `Agen…
- CVE-2026-57117HIGHCVSS 8.8EG 8.8✓ Fixed in 4.6.592026-06-18
vulnerable: 4.6.10 ... 4.6.58 (47 versions)
PraisonAI: Compute-bridged file tools allow shell command injection # Compute-bridged file tools allow shell command injection ## Summary `LocalManagedAgent` / `SandboxedAgent` compute bridging wraps `read_file`, `list_files`, and `writ…
- CVE-2026-57119HIGHCVSS 7.5EG 7.5✓ Fixed in 4.6.592026-06-18
vulnerable: 0.0.1 ... 4.6.9 (749 versions)
PraisonAI: Unauthenticated Local File Inclusion via agent_file path in PraisonAI Jobs API ### Summary An unauthenticated attacker can read arbitrary files on the server by supplying an absolute filesystem path in the `agent_file` field of…
- CVE-2026-57122HIGHCVSS 8.6EG 8.6✓ Fixed in 4.6.592026-06-18
vulnerable: 0.0.1 ... 4.6.9 (749 versions)
PraisonAI: Webhook signature verification skipped (fail-open) when secret unset, allowing forged inbound webhooks (WhatsApp & Linear bots) The WhatsApp and Linear bot adapters verify the inbound webhook HMAC signature only when a secret i…
- CVE-2026-57124CRITICALCVSS 9.8EG 9.8✓ Fixed in 4.6.592026-06-18
vulnerable: 0.0.1 ... 4.6.9 (749 versions)
PraisonAI: Missing Authentication for Critical Function and Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in praisonai # Unauthenticated PraisonAI UI MCP connect endpoint executes attacker-chos…
- CVE-2026-57125CRITICALCVSS 9.8EG 9.8✓ Fixed in 4.6.592026-06-18
vulnerable: 0.0.1 ... 4.6.9 (749 versions)
PraisonAI: Unauthenticated RCE via Jobs API + Approval Bypass # Unauthenticated Remote Code Execution via Jobs API and Approval Bypass in PraisonAI ## Summary An unauthenticated attacker can execute arbitrary OS commands on any serve…
- CVE-2026-57127CRITICALCVSS 9.8EG 9.8✓ Fixed in 4.6.592026-06-18
vulnerable: 0.0.1 ... 4.6.9 (749 versions)
praisonai: recipe serve auth middleware silently disables itself when no secret is set # praisonai: `recipe serve` authentication middleware silently disables itself when no secret is set **Researcher:** Kai Aizen — SnailSploit (@Snail…
- CVE-2026-57131CRITICALCVSS 9.8EG 9.8✓ Fixed in 4.6.592026-06-18
vulnerable: 0.0.1 ... 4.6.9 (749 versions)
PraisonAI: Jobs API exposes agent-execution endpoints with no authentication # praisonai: Jobs API exposes agent-execution endpoints with no authentication **Researcher:** Kai Aizen — SnailSploit (@SnailSploit), Adversarial & Offensiv…
- CVE-2026-57132HIGHCVSS 8.2EG 8.2✓ Fixed in 4.6.612026-06-18
vulnerable: 0.0.1 ... 4.6.9 (751 versions)
PraisonAI: PRAISONAI_CALL_AUTH=disabled environment variable unconditionally disables authentication ### Summary Setting `PRAISONAI_CALL_AUTH=disabled` completely disables all authentication on the `/api/v1/agents/{id}/invoke` endpoint. T…
- CVE-2026-57142HIGHCVSS 7.8EG 7.8✓ Fixed in 4.6.612026-06-18
vulnerable: 4.5.100 ... 4.6.9 (103 versions)
PraisonAI recipe workflow policy can be bypassed by declaring and YAML-approving dangerous tools outside TEMPLATE.yaml ## Summary PraisonAI recipe execution has a dangerous-tool policy that is supposed to block default-denied tools unles…
- CVE-2026-57144HIGHCVSS 8.8EG 8.8✓ Fixed in 4.6.612026-06-18
vulnerable: 4.5.110 ... 4.6.9 (83 versions)
PraisonAI SandlockSandbox falls back to unrestricted subprocess execution when Landlock is unavailable ## Summary `praisonai.sandbox.SandlockSandbox` is documented and implemented as the kernel-enforced sandbox backend for untrusted code…
- CVE-2026-57145CRITICALCVSS 9.1EG 9.1✓ Fixed in 4.6.612026-06-18
vulnerable: 0.0.1 ... 4.6.9 (751 versions)
PraisonAI: Arbitrary File Read/Write via `multiedit` Tool Without Path Validation ## Summary The `multiedit` tool in `src/praisonai/praisonai/tools/multiedit.py` allows LLM-controlled arbitrary file read and write without any path valida…
- CVE-2026-57146HIGHCVSS 7.5EG 7.5✓ Fixed in 4.6.612026-06-18
vulnerable: 4.5.115 ... 4.6.9 (78 versions)
PraisonAI A2U incomplete authentication fix leaves current serve command unauthenticated by default ## Summary The published A2U advisory `GHSA-f292-66h9-fpmf` says unauthenticated A2U event streaming was fixed in `praisonai` `4.5.115`. …
- CVE-2026-64824HIGHCVSS 8.4EG 8.4✓ Fixed in 4.6.402026-07-21
vulnerable: 0.0.1 ... 4.6.9 (731 versions)
Home Assistant Core before 2026.7.0 contains a path traversal vulnerability in the backup-restore function that allows attackers to write files to arbitrary absolute filesystem paths by supplying a crafted tar archive with a SYMTYPE entry …
Check whether praisonai is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for praisonai CVEs against the assets you own.
Start Free Scan →