Mervin Praison PraisonAI是Mervin Praison个人开发者开源的一个低代码多智能体协作框架。 Mervin Praison PraisonAI 4.6.40之前版本存在安全漏洞,该漏洞源于A2A JSON-RPC端点未经身份验证开放,并注册了使用Python eval()实现的calculate工具,可能导致未经身份验证的远程攻击者通过发送message/send请求到/a2a,利用LLM调用calculate工具在服务器进程中执行任意Python代码,并暴露任务历史和任务取
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| MervinPraison | PraisonAI | < 4.6.40 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| MervinPraison | PraisonAI | < 4.6.40 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2026-47392 | 9.9 CRITICAL | PraisonAI vulnerable to sandbox escape via `print.__self__` builtins module leak in `execu |
| CVE-2026-47393 | 9.8 CRITICAL | PraisonAI `deploy --type api` emits a Flask server with authentication disabled by default |
| CVE-2026-47396 | 9.8 CRITICAL | PraisonAI call server exposes unauthenticated agent listing, invocation, and deletion when |
| CVE-2026-47410 | 9.8 CRITICAL | praisonai-platform: JWT signing key defaults to hardcoded "dev-secret-change-me", allowing |
| CVE-2026-47413 | 9.6 CRITICAL | praisonai-platform: Any workspace member can add arbitrary user as owner via POST /workspa |
| CVE-2026-47416 | 9.6 CRITICAL | praisonai-platform: Any workspace member can promote themselves (or any other member) to o |
| CVE-2026-47405 | 8.8 HIGH | PraisonAI Platform missing role checks let any workspace member become owner and take over |
| CVE-2026-47399 | 8.8 HIGH | PraisonAI Platform workspace-scoped routes allow cross-workspace object access by global o |
| CVE-2026-47415 | 8.3 HIGH | praisonai-platform: Issue endpoints accept any issue_id without workspace ownership check, |
| CVE-2026-47419 | 8.3 HIGH | praisonai-platform: Agent endpoints accept any agent_id without workspace ownership check, |
| CVE-2026-47409 | 8.1 HIGH | praisonai-platform: Any workspace member can remove any other member (including the owner) |
| CVE-2026-47417 | 8.1 HIGH | praisonai-platform: Comment endpoints accept any issue_id without workspace ownership chec |
| CVE-2026-47412 | 8.1 HIGH | praisonai-platform: Any workspace member can delete the entire workspace via DELETE /works |
| CVE-2026-47418 | 8.1 HIGH | praisonai-platform: Project endpoints accept any project_id without workspace ownership ch |
| CVE-2026-47406 | 8.1 HIGH | praisonai-platform: Dependency endpoints accept any issue_id and dep_id without workspace |
| CVE-2026-47398 | 8.1 HIGH | PraisonAI: Arbitrary code execution via unguarded `spec.loader.exec_module` in `agents_gen |
| CVE-2026-47414 | 7.6 HIGH | praisonai-platform: Label endpoints accept any label_id and any issue_id without workspace |
| CVE-2026-47397 | 7.1 HIGH | PraisonAI has an Arbitrary File Write in Python API |
| CVE-2026-47408 | 6.5 MEDIUM | praisonai-platform: list_issue_activity returns activity log for any issue regardless of w |
| CVE-2026-47411 | 6.5 MEDIUM | praisonai-platform: Any workspace member can rewrite workspace name, description, and sett |
Showing top 20 of 25 CVEs. View all on vendor page → →
No comments yet