PraisonAI是Mervin Praison个人开发者的一个低代码多智能体协作框架。 PraisonAI 4.5.128之前版本存在路径遍历漏洞,该漏洞源于recipe CLI解压.praison归档时未验证路径,可能导致任意文件覆盖。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| MervinPraison | PraisonAI | < 4.5.128 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-40158 | 8.6 HIGH | PraisonAI has Improper Control of Generation of Code ('Code Injection') and Protection Mec |
| CVE-2026-40156 | 7.8 HIGH | PraisonAI Affected by Implicit Execution of Arbitrary Code via Automatic `tools.py` Loadin |
| CVE-2026-40159 | 5.5 MEDIUM | PraisonAI Exposes Sensitive Environment Variable via Untrusted MCP Subprocess Execution |
| CVE-2026-40160 | PraisonAIAgents has SSRF via unvalidated URL in `web_crawl` httpx fallback |
No comments yet