Mervin Praison PraisonAI是Mervin Praison个人开发者开源的一个低代码多智能体协作框架。 Mervin Praison PraisonAI 4.6.40之前版本存在服务端请求伪造漏洞,该漏洞源于spider_tools URL验证绕过,可能导致服务端请求伪造攻击。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| MervinPraison | PraisonAI | < 4.6.40 |
affected |
| MervinPraison | praisonaiagents | < 1.6.40 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| MervinPraison | PraisonAI | < 4.6.40 | - |
|
| MervinPraison | praisonaiagents | < 1.6.40 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-47392 | 9.9 CRITICAL | PraisonAI vulnerable to sandbox escape via `print.__self__` builtins module leak in `execu |
| CVE-2026-47393 | 9.8 CRITICAL | PraisonAI `deploy --type api` emits a Flask server with authentication disabled by default |
| CVE-2026-47396 | 9.8 CRITICAL | PraisonAI call server exposes unauthenticated agent listing, invocation, and deletion when |
| CVE-2026-47391 | 9.8 CRITICAL | PraisonAI's unauthenticated A2A official example can reach real LLM-driven `eval()` tool e |
| CVE-2026-47410 | 9.8 CRITICAL | praisonai-platform: JWT signing key defaults to hardcoded "dev-secret-change-me", allowing |
| CVE-2026-47413 | 9.6 CRITICAL | praisonai-platform: Any workspace member can add arbitrary user as owner via POST /workspa |
| CVE-2026-47416 | 9.6 CRITICAL | praisonai-platform: Any workspace member can promote themselves (or any other member) to o |
| CVE-2026-47405 | 8.8 HIGH | PraisonAI Platform missing role checks let any workspace member become owner and take over |
| CVE-2026-47399 | 8.8 HIGH | PraisonAI Platform workspace-scoped routes allow cross-workspace object access by global o |
| CVE-2026-47415 | 8.3 HIGH | praisonai-platform: Issue endpoints accept any issue_id without workspace ownership check, |
| CVE-2026-47419 | 8.3 HIGH | praisonai-platform: Agent endpoints accept any agent_id without workspace ownership check, |
| CVE-2026-47417 | 8.1 HIGH | praisonai-platform: Comment endpoints accept any issue_id without workspace ownership chec |
| CVE-2026-47412 | 8.1 HIGH | praisonai-platform: Any workspace member can delete the entire workspace via DELETE /works |
| CVE-2026-47418 | 8.1 HIGH | praisonai-platform: Project endpoints accept any project_id without workspace ownership ch |
| CVE-2026-47409 | 8.1 HIGH | praisonai-platform: Any workspace member can remove any other member (including the owner) |
| CVE-2026-47406 | 8.1 HIGH | praisonai-platform: Dependency endpoints accept any issue_id and dep_id without workspace |
| CVE-2026-47398 | 8.1 HIGH | PraisonAI: Arbitrary code execution via unguarded `spec.loader.exec_module` in `agents_gen |
| CVE-2026-47414 | 7.6 HIGH | praisonai-platform: Label endpoints accept any label_id and any issue_id without workspace |
| CVE-2026-47397 | 7.1 HIGH | PraisonAI has an Arbitrary File Write in Python API |
| CVE-2026-47408 | 6.5 MEDIUM | praisonai-platform: list_issue_activity returns activity log for any issue regardless of w |
Showing top 20 of 25 CVEs. View all on vendor page → →
No comments yet